[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [RFR] webwml://security/2005/dsa-880.wml

On Wed, Nov 02, 2005 at 06:42:16PM +0100, Simon Paillard wrote:
> Je joins le correctif pour la VO (s'il est appliqué à toutes les
> langues, il faudrait passer la version dans l'entête de la VF).
> Merci d'avance pour vos relectures.

Le même avec un correctif de la vo bien balisé.

Simon Paillard
<define-tag description>several vulnerabilities</define-tag>
<define-tag moreinfo>
<p>Several cross-site scripting vulnerabilities have been discovered in
phpmyadmin, a set of PHP-scripts to administrate MySQL over the WWW.
The Common Vulnerabilities and Exposures project identifies the
following problems:</p>


<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2869";>CAN-2005-2869</li>

    <p>Andreas Kerber and Michal Cihar discovered several cross-site
    scripting vulnerabilities in the error page and in the cookie

<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3300";>CVE-2005-3300</li>

    <p>Stefan Esser discovered missing safety checks in grab_globals.php
    that could allow an attacker to induce phpmyadmin to include an
    arbitrary local file.</p></li>

<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3301";>CVE-2005-3301</li>

    <p>Tobias Klein discovered several cross-site scripting
    vulnerabilities that could allow attackers to inject arbitrary
    HTML or client-side scripting.</p></li>


<p>The version in the old stable distribution (woody) has probably its
own flaws and is not easily fixable without a full audit and patch
session.  The easier way is to upgrade it from woody to sarge.</p>

<p>For the stable distribution (sarge) these problems have been fixed in
version 2.6.2-3sarge1.</p>

<p>For the unstable distribution (sid) these problems have been fixed in
version 2.6.4-pl1-1.</p>

<p>We recommend that you upgrade your phpmyadmin package.</p>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2005/dsa-880.data"
# $Id: dsa-880.wml,v 1.1 2005/11/02 11:14:36 joey Exp $

Reply to: