Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 26: FEDORA-2018-147d33439c Moderate: phpMyAdmin Self-XSS Fix

fedora
Calendar Grey March 1, 2018
Dist Fedora Esm H88
phpMyAdmin 4.7.9 launched, addressing critical XSS security flaw, advising users to update immediately.
From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes

Summary

Translation API for PHP using Gettext MO files.

Features

* All strings are stored in memory for fast lookup

* Fast loading of MO files

* Low level API for reading MO files

* Emulation of Gettext API

* No use of eval() for plural equation

Limitations

* Not suitable for huge MO files which you don't want to store in memory

* Input and output encoding has to match (preferably UTF-8)

Autoloader: /usr/share/php/PhpMyAdmin/MoTranslator/autoload.php

From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released**

Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular

maintenance bug fixes. The security fix relates to a self-XSS vulnerability in

the central columns feature that is reported as PMASA-2018-1

https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya

https://www.linkedin.com/in/mayur-udiniya-09247b129/ for finding and responsibly

disclosing this flaw. We recommend all users upgrade to resolve this security

problem. A complete list of new features and bugs that have been fixed is

available in the ChangeLog file or changelog.php included with this release.

Notable changes since 4.7.7: * Fixed error handling with PHP 7.2 * Fixed

resetting default setting values * Fixed fallback value for collation

connection Additionally, there have been continuous improvements to many of the

translations. If you don't see your language or find a problem, you can

contribute too; see https://www.phpmyadmin.net/translate/ for details.

[ 1 ] Bug #1547748 - CVE-2018-7260 phpMyAdmin: XSS in db_central_columns.php

https://bugzilla.redhat.com/show_bug.cgi?id=1547748

su -c 'dnf upgrade php-phpmyadmin-motranslator' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 26
Version: 4.0
Release: 1.fc26
Summary: Translation API for PHP using Gettext MO files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here