![]() |
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ....
|
Guardian Digital Inc. > InfoCenter > Mailing List Archives > BugTraq BugTraq Mailing List Archive
From: Sune Kloppenborg Jeppesen (jaervosz@gentoo.org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
phpMyAdmin contains multiple vulnerabilities which could lead to file
Background
phpMyAdmin is a tool written in PHP intended to handle the
Affected packages
-------------------------------------------------------------------
Description
Nicolas Gregoire (exaprobe.com) has discovered two vulnerabilities that
Impact
On a system where external MIME-based transformations are enabled, an
Workaround
You can temporarily enable PHP safe_mode or disable external MIME-based
Resolution
All phpMyAdmin users should upgrade to the latest version:
# emerge --sync
References
[ 1 ] CAN-2004-1147
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200412-19.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Foundation, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/2.0
This e-mail transmission contains information that is confidential and may be privileged. It is intended only for the addressee(s) named above. If you receive this e-mail in error, please do not read, copy or disseminate it in any manner. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please reply to the message immediately by informing the sender that the message was misdirected. After replying, please erase it from your computer system. Your assistance in correcting this error is appreciated.
_______________________________________________
This e-mail transmission contains information that is confidential and may be privileged. It is intended only for the addressee(s) named above. If you receive this e-mail in error, please do not read, copy or disseminate it in any manner. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please reply to the message immediately by informing the sender that the message was misdirected. After replying, please erase it from your computer system. Your assistance in correcting this error is appreciated.
|