Bug 34339 - php-adodb new security issue CVE-2025-46337
Summary: php-adodb new security issue CVE-2025-46337
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-02 16:02 CEST by Nicolas Salguero
Modified: 2025-06-08 08:23 CEST (History)
5 users (show)

See Also:
Source RPM: php-adodb-5.22.6-1.mga9.src.rpm
CVE: CVE-2025-46337
Status comment: Fixed upstream in 5.22.9 and patch available from upstream and Ubuntu


Attachments

Description Nicolas Salguero 2025-06-02 16:02:37 CEST
Ubuntu has issued an advisory on May 29:
https://ubuntu.com/security/notices/USN-7530-1

Fix: https://github.com/ADOdb/ADOdb/commit/11107d6d6e5160b62e05dff8a3a2678cf0e3a426
Nicolas Salguero 2025-06-02 16:03:14 CEST

Status comment: (none) => Fixed upstream in 5.22.9 and patch available from upstream and Ubuntu
Source RPM: (none) => php-adodb-5.22.6-1.mga9.src.rpm
CVE: (none) => CVE-2025-46337

Comment 1 Marja Van Waes 2025-06-05 21:07:54 CEST
Assigning to the registered maintainer, cc'ing the php stack maintainers.

Assignee: bugsquad => mageia
CC: (none) => marja11, php

Comment 2 Marc Krämer 2025-06-06 00:16:23 CEST
An possible SQL injection for php-adodb was found.
Apart from that, this release brings some minor bug fixes



References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46337
https://ubuntu.com/security/notices/USN-7530-1
https://github.com/ADOdb/ADOdb/releases/tag/v5.22.9
------------------------------------------------

RPMs in core/upates_testing:
php-adodb-5.22.9-1.mga9.noarch.rpm


SRPM:
php-adodb-5.22.9-1.mga9.src.rpm

Assignee: mageia => qa-bugs

Comment 3 Herman Viaene 2025-06-06 12:05:15 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Remark that this laptop runs mysql and LO Base; but the current version was not installed.
Ref bug 30008, OK on clean install.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

katnatek 2025-06-07 01:40:04 CEST

CC: (none) => andrewsfarm
Keywords: (none) => advisory

Comment 4 Thomas Andrews 2025-06-07 02:02:25 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 5 Mageia Robot 2025-06-08 08:23:35 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0179.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.