Bug 5289 - phpmyadmin is newer in MDV 2010.2 (contrib) updates than Mageia 1
Summary: phpmyadmin is newer in MDV 2010.2 (contrib) updates than Mageia 1
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-04-08 15:59 CEST by David Walser
Modified: 2012-04-13 20:50 CEST (History)
5 users (show)

See Also:
Source RPM: phpmyadmin-3.4.9-1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-04-08 15:59:49 CEST
Mandriva has done it again.  They updated phpmyadmin to 3.5.0.

Now we'll need to freeze push it in Cauldron and update it in 1.
David Walser 2012-04-08 16:00:10 CEST

CC: (none) => lists.jjorge

Comment 1 Remco Rijnders 2012-04-10 10:00:20 CEST
Assigning to maintainer

Assignee: bugsquad => lists.jjorge

Comment 2 José Jorge 2012-04-12 21:16:03 CEST
Submitted phpmyadmin-3.5.0-1.mga1 to testing.
Push to Cauldron asked.

Status: NEW => ASSIGNED
Assignee: lists.jjorge => qa-bugs

Comment 3 David Walser 2012-04-12 22:11:29 CEST
Thanks José.

Advisory:
========================

Updated phpmyadmin package fixes security vulnerabilities:

It was possible to conduct XSS using a crafted database name in phpMyAdmin
3.4.x before 3.4.10.2.  The victim would have to willingly click on a
database name which clearly shows a possible XSS (CVE-2012-1190).

show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a
configuration file does not exist, allows remote attackers to obtain
sensitive information via a direct request, which reveals the installation
path in an error message about this missing file (CVE-2012-1902).

This update also allows upgrading from Mandriva 2010.2.

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1190
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1902
http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php
http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.php
========================

Updated packages in core/updates_testing:
========================
phpmyadmin-3.5.0-1.mga1

from phpmyadmin-3.5.0-1.mga1.src.rpm
Comment 4 Derek Jennings 2012-04-13 00:00:51 CEST
Update Validated

Upgraded production phpmyadmin to phpmyadmin-3.5.0-1.mga1
Confirmed no regressions in normal operation with databases.

Could sysadmin please push phpmyadmin-3.5.0-1.mga1.src.rpm  from core/updates_testing to core/updates




Advisory:
========================

Updated phpmyadmin package fixes security vulnerabilities:

It was possible to conduct XSS using a crafted database name in phpMyAdmin
3.4.x before 3.4.10.2.  The victim would have to willingly click on a
database name which clearly shows a possible XSS (CVE-2012-1190).

show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a
configuration file does not exist, allows remote attackers to obtain
sensitive information via a direct request, which reveals the installation
path in an error message about this missing file (CVE-2012-1902).

This update also allows upgrading from Mandriva 2010.2.

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1190
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1902
http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php
http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.php
========================

Keywords: (none) => validated_update
CC: (none) => derekjenn, sysadmin-bugs

Comment 5 Dave Hodgins 2012-04-13 05:05:30 CEST
Testing complete on i586 for the srpm
phpmyadmin-3.5.0-1.mga1.src.rpm

Just browsing through https://localhost/phpmyadmin, created a table,
and dropped it.

CC: (none) => davidwhodgins

Comment 6 Dave Hodgins 2012-04-13 05:14:52 CEST
Derek, which arch did you test on?  Most updates shouldn't be validated
until they have been tested on both architectures.
Comment 7 Derek Jennings 2012-04-13 09:26:42 CEST
I was using x86_64 but phpmyadmin is .noarch so it should not matter.
Comment 8 Thomas Backlund 2012-04-13 19:54:14 CEST
Update pushed

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED

Comment 9 Dave Hodgins 2012-04-13 20:50:58 CEST
(In reply to comment #7)
> I was using x86_64 but phpmyadmin is .noarch so it should not matter.

Sorry, you're right.  My mistake.

Note You need to log in before you can comment on or make changes to this bug.