Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1689-1

Опубликовано: 02 июл. 2019
Источник: suse-cvrf

Описание

Security update for phpMyAdmin

This update for phpMyAdmin fixes the following issues:

phpMyAdmin was updated to 4.9.0.1:

  • Several issues with SYSTEM VERSIONING tables
  • Fixed json encode error in export
  • Fixed JavaScript events not activating on input (sql bookmark issue)
  • Show Designer combo boxes when adding a constraint
  • Fix edit view
  • Fixed invalid default value for bit field
  • Fix several errors relating to GIS data types
  • Fixed javascript error PMA_messages is not defined
  • Fixed import XML data with leading zeros
  • Fixed php notice, added support for 'DELETE HISTORY' table privilege (MariaDB >= 10.3.4)
  • Fixed MySQL 8.0.0 issues with GIS display
  • Fixed 'Server charset' in 'Database server' tab showing wrong information
  • Fixed can not copy user on Percona Server 5.7
  • Updated sql-parser to version 4.3.2, which fixes several parsing and linting problems

Список пакетов

SUSE Package Hub 12
phpMyAdmin-4.9.0.1-bp150.31.1
SUSE Package Hub 15
phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.0
phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.1
phpMyAdmin-4.9.0.1-bp150.31.1

Описание

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.


Затронутые продукты
SUSE Package Hub 12:phpMyAdmin-4.9.0.1-bp150.31.1
SUSE Package Hub 15:phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.0:phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.1:phpMyAdmin-4.9.0.1-bp150.31.1

Ссылки

Описание

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.


Затронутые продукты
SUSE Package Hub 12:phpMyAdmin-4.9.0.1-bp150.31.1
SUSE Package Hub 15:phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.0:phpMyAdmin-4.9.0.1-bp150.31.1
openSUSE Leap 15.1:phpMyAdmin-4.9.0.1-bp150.31.1

Ссылки