[SECURITY] [DLA 2580-1] adminer security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -----------------------------------------------------------------------
Debian LTS Advisory DLA-2580-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Utkarsh Gupta
March 03, 2021 https://wiki.debian.org/LTS
- -----------------------------------------------------------------------
Package : adminer
Version : 4.2.5-3+deb9u2
CVE ID : CVE-2021-21311
Adminer is an open-source database management in a single PHP file.
In adminer from version 4.0.0 and before 4.7.9 there is a
server-side request forgery vulnerability. Users of Adminer versions
bundling all drivers (e.g. `adminer.php`) are affected.
For Debian 9 stretch, this problem has been fixed in version
4.2.5-3+deb9u2.
We recommend that you upgrade your adminer packages.
For the detailed security status of adminer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/adminer
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmA+lBgACgkQgj6WdgbD
S5aV8A/8C5cnxao31Xs/19/4FbLwQLlwLonNfLeEGVj8R0fHDJVAELcQk61UeHc5
CDCL8aokfTDF8Za+kPd4usZLdktcHhTZEzHYX5aCJ96iXYuK4CkB48cYZul6kBKk
9+oBBiYazANYHx426SXXr1rm/snWMCaF/yvFQ9HqZlrbNK8xKNrEOHT9/MBPIO/R
iv0vbBAxfc/9vo05yChHUI7N7G7qnZHG0sFMIqkl4zcYq3C05ukyfRvNWRxQ4qUD
NvzdTgzHM5c4579o8I6bQwFGdbxWIplgufbEiwNotkuarOSm6Pw6qpxR484ygCkT
2/BDLyxrLb4E/qRpkaY81kmYKVUMMWHQwzgOUkyJieT0kuPxPQjAdHik6vxG3hvk
C6LqESp+HvljPeSa0eIKODyXF+Q7O66E43ebXbOTsOcZgWJlnVO51+jUQzV/0EDw
8gGPM1AiCF5phxBiK5T9ncTSMdJtzGWnywVl9VOYRtd2GGAGy9Xik/aRaafGA6Vs
R5U4d5uIvNd6b5fFbBfaxlkv681IHts61dMhzzC/kZwSSuv8ADeWUmiLX/EqaiFf
d+eJWYFXhSxR+DlwiCoH9Bw9EjIt+N9cl7EvhVXmLiDZiBi8cFoY+/qO6WNoumUv
h/jdaf1bgPLMwwP71bg/tPsUQNsGtlxz+43BfqfEreZ+GqpeZlQ=
=c2KF
-----END PGP SIGNATURE-----
Reply to: