i was looking at the link as provided in redhat's announcement. this seems to be CVE-2009-1285, which debian is already tracking as unimportant. however, the phpmyadmin page considers the issue to be critical. perhaps the debian severity is too low?
mike -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org