Bug#508026: register_globals on is not supported

2008-12-23 Thread Giuseppe Iuculano
Hi, Giuseppe Iuculano ha scritto: > Hi, > > Nico Golde ha scritto: >> I take care of sponsoring the upload for unstable. For >> stable security the version looks wrong to me, please use >> 4.0.1-3.1etch1. > > Right, attached the new debdiff. > > Giuseppe. > Attached a new proposed debdiff t

Bug#508026: register_globals on is not supported

2008-12-23 Thread Giuseppe Iuculano
Hi, Nico Golde ha scritto: > I take care of sponsoring the upload for unstable. For > stable security the version looks wrong to me, please use > 4.0.1-3.1etch1. Right, attached the new debdiff. Giuseppe. diff -u phppgadmin-4.0.1/debian/changelog phppgadmin-4.0.1/debian/changelog --- phppgadmi

Bug#508026: register_globals on is not supported

2008-12-23 Thread Nico Golde
Hi, * Giuseppe Iuculano [2008-12-23 14:50]: > Thijs Kinkhorst ha scritto: > > As it seems, upstream does already support running in register_globals=0 > > mode > > for a long time (according to their changelog since 2002...). Therefore I > > guess this bug would be fixed if the statement turnin

Bug#508026: register_globals on is not supported

2008-12-23 Thread Giuseppe Iuculano
tags 508026 fixed-upstream thanks Hi, Thijs Kinkhorst ha scritto: > As it seems, upstream does already support running in register_globals=0 mode > for a long time (according to their changelog since 2002...). Therefore I > guess this bug would be fixed if the statement turning register_globals

Bug#508026: register_globals on is not supported

2008-12-14 Thread Thijs Kinkhorst
On Sunday 14 December 2008 12:53, Giuseppe Iuculano wrote: > Thijs Kinkhorst ha scritto: > > As it seems, upstream does already support running in register_globals=0 > > mode for a long time (according to their changelog since 2002...). > > Therefore I > > Where did you read that? In TODO file I re

Bug#508026: register_globals on is not supported

2008-12-14 Thread Giuseppe Iuculano
Hi Thijs, Thijs Kinkhorst ha scritto: > As it seems, upstream does already support running in register_globals=0 mode > for a long time (according to their changelog since 2002...). Therefore I Where did you read that? In TODO file I read "* register_globals off support". Cheers, Giuseppe.

Bug#508026: register_globals on is not supported

2008-12-14 Thread Thijs Kinkhorst
retitle 508026 register_globals on is not supported thanks Hi, Thank you Giuseppe for your work; however, please do not upload it as it doesn't address the root cause. > Note that the vulnerability can only be exploited when register_globals=on > (which is the default in /etc/phppgadmin/apache