Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 27: a1650ed14f moderate: phpMyAdmin Self-XSS Threat

fedora
Calendar Grey February 26, 2018
Dist Fedora Esm H88
An important security fix for Fedora 27 resolves a self-XSS vulnerability in phpMyAdmin version 4.7.8. Promptly updating is advised.
From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes

Summary

Translation API for PHP using Gettext MO files.

Features

* All strings are stored in memory for fast lookup

* Fast loading of MO files

* Low level API for reading MO files

* Emulation of Gettext API

* No use of eval() for plural equation

Limitations

* Not suitable for huge MO files which you don't want to store in memory

* Input and output encoding has to match (preferably UTF-8)

Autoloader: /usr/share/php/PhpMyAdmin/MoTranslator/autoload.php

From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released**

Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular

maintenance bug fixes. The security fix relates to a self-XSS vulnerability in

the central columns feature that is reported as PMASA-2018-1

https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya

https://www.linkedin.com/in/mayur-udiniya-09247b129/ for finding and responsibly

disclosing this flaw. We recommend all users upgrade to resolve this security

problem. A complete list of new features and bugs that have been fixed is

available in the ChangeLog file or changelog.php included with this release.

Notable changes since 4.7.7: * Fixed error handling with PHP 7.2 * Fixed

resetting default setting values * Fixed fallback value for collation

connection Additionally, there have been continuous improvements to many of the

translations. If you don't see your language or find a problem, you can

contribute too; see https://www.phpmyadmin.net/translate/ for details.

[ 1 ] Bug #1547748 - CVE-2018-7260 phpMyAdmin: XSS in db_central_columns.php

https://bugzilla.redhat.com/show_bug.cgi?id=1547748

su -c 'dnf upgrade php-phpmyadmin-motranslator' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 27
Version: 4.0
Release: 1.fc27
Summary: Translation API for PHP using Gettext MO files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here