Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE: 2019:1861-1 Moderate: phpMyAdmin CSRF and SQL Injection

opensuse
Calendar Grey August 14, 2019
Dist Opensuse Esm H88
openSUSE announces a patch for phpMyAdmin correcting two vulnerabilities: CSRF and SQL injection flaws.
An update that fixes two vulnerabilities is now available.

Description

This update for phpMyAdmin fixes the following issues:

phpMyAdmin was updated to 4.9.0.1:

* Several issues with SYSTEM VERSIONING tables

* Fixed json encode error in export

* Fixed JavaScript events not activating on input (sql bookmark issue)

* Show Designer combo boxes when adding a constraint

* Fix edit view

* Fixed invalid default value for bit field

* Fix several errors relating to GIS data types

* Fixed javascript error PMA_messages is not defined

* Fixed import XML data with leading zeros

* Fixed php notice, added support for 'DELETE HISTORY' table privilege

(MariaDB >= 10.3.4)

* Fixed MySQL 8.0.0 issues with GIS display

* Fixed "Server charset" in "Database server" tab showing wrong information

* Fixed can not copy user on Percona Server 5.7

* Updated sql-parser to version 4.3.2, which fixes several parsing and

linting problems

- boo#1137497 / PMASA-2019-4 / CVE-2019-12616 / CWE-661: Fixed CSRF

vulnerability...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-1861=1

Package List

- openSUSE Backports SLE-15-SP1 (noarch):

phpMyAdmin-4.9.0.1-bp151.3.3.1

References

https://www.suse.com/security/cve/CVE-2019-11768.html

https://www.suse.com/security/cve/CVE-2019-12616.html

https://bugzilla.suse.com/1137496

https://bugzilla.suse.com/1137497

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1861-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here