Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 43 pgAdmin 4 Update Advisory 2026-a0d40b97a8 Denial of Service

Refresh vendored bundle. fixes multiple CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0d40b97a8 2026-03-02 00:40:42.980496+00:00 -------------------------------------------------------------------------------- Name : pgadmin4 Product : Fedora 43 Version : 9.12 Release : 2.fc43 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. -------------------------------------------------------------------------------- Update Information: Refresh vendored bundle. fixes multiple CVEs. -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 21 2026 Sandro Mani - 9.12-2 - Refresh vendor bundle, fixes svelte CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2439021 - CVE-2026-25639 pgadmin4: Axios affected by Denial of Service via __proto__ Key in mergeConfig [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2439021 [ 2 ] Bug #2439027 - CVE-2026-25639 pgadmin4: Axios affected by Denial of Service via __proto__ Key in mergeConfig [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2439027 [ 3 ] Bug #2441546 - CVE-2026-27125 pgadmin4: Svelte SSR attribute spreading includes inherited properties from prototype chain [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441546 [ 4 ] Bug #2441547 - CVE-2026-27122 pgadmin4: Svelte SSR does not validate dynamic element tag names in ` ` [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441547 [ 5 ] Bug #2441548 - CVE-2026-27125 pgadmin4: Svelte SSR attribute spreading includes inherited properties from prototype chain [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441548 [ 6 ] Bug #2441549 - CVE-2026-27121 pgadmin4: Svelte affected by cross-site scripting via spread attributes in Svelte SSR [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441549 [ 7 ] Bug #2441550 - CVE-2026-27119 pgadmin4: Svelte affected by XSS in SSR ` ` element [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441550 [ 8 ] Bug #2441551 - CVE-2026-27122 pgadmin4: Svelte SSR does not validate dynamic element tag names in ` ` [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441551 [ 9 ] Bug #2441552 - CVE-2026-27121 pgadmin4: Svelte affected by cross-site scripting via spread attributes in Svelte SSR [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441552 [ 10 ] Bug #2441553 - CVE-2026-27119 pgadmin4: Svelte affected by XSS in SSR ` ` element [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441553 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0d40b97a8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Donot reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Refresh vendor bundle for pgAdmin 4 addresses multiple CVEs on Fedora 43 affecting security and stability.. pgadmin4 security update, Fedora 43 advisory, Denial of Service pgAdmin, Svelte XSS fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 02, 2026 Critical Fedora
197

Debian 11: DLA-4121-1 moderate: phpMyAdmin XSS security update

Multiple XSS vulnerabilities have been fixed in phpMyAdmin, an administration tool for MySQL and MariaDB databases. CVE-2023-25727 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4121-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk April 08, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : phpmyadmin Version : 4:5.0.4+dfsg2-2+deb11u2 CVE ID : CVE-2023-25727 CVE-2025-24529 CVE-2025-24530 Multiple XSS vulnerabilities have been fixed in phpMyAdmin, an administration tool for MySQL and MariaDB databases. CVE-2023-25727 XSS vulnerability in drag-and-drop upload CVE-2025-24529 XSS on Insert page CVE-2025-24530 XSS when checking tables For Debian 11 bullseye, these problems have been fixed in version 4:5.0.4+dfsg2-2+deb11u2. We recommend that you upgrade your phpmyadmin packages. For the detailed security status of phpmyadmin please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/phpmyadmin Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Various XSS vulnerabilities fixed in phpMyAdmin for Debian 11; suggested update is now accessible.. phpMyAdmin Security, Debian LTS Advisory, XSS Fixes, Database Administration. . LinuxSecurity.com Team

Calendar%202 Apr 08, 2025 Debian LTS
89

Fedora 38: FEDORA-2023-8cc61c8b14 critical: pgAdmin4 Remote Code Execution

Backport fix for CVE-2023-5002.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-8cc61c8b14 2023-10-04 15:50:14.488489 -------------------------------------------------------------------------------- Name : pgadmin4 Product : Fedora 38 Version : 6.21 Release : 3.fc38 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-5002. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Sandro Mani - 6.21-3 - Backport patch for CVE-2023-5002 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2240071 - CVE-2023-5002 pgadmin4: remote code execution by an authenticated user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2240071 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-8cc61c8b14' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code ofConduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Implement patch addressing CVE-2023-5002 in pgAdmin4 on Fedora 38. This update includes relevant specifics, threat level assessment, and steps for installation.. pgAdmin4 Update, Fedora 38, Remote Code Execution, Backport Fix, Open Source Database. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2023 Critical Fedora
89

Fedora 36: 2023-0334c6000a Critical: pgAdmin4 URL Redirect Risk

Update to pgadmin4-6.19. ---- Backport fix for CVE-2023-22298.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0334c6000a 2023-02-02 02:01:53.366758 --------------------------------------------------------------------------------Name : pgadmin4 Product : Fedora 36 Version : 6.19 Release : 1.fc36 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. --------------------------------------------------------------------------------Update Information: Update to pgadmin4-6.19. ---- Backport fix for CVE-2023-22298. --------------------------------------------------------------------------------ChangeLog: * Thu Jan 19 2023 Sandro Mani - 6.19-1 - Update to 6.19 * Wed Jan 18 2023 Benjamin A. Beasley - 6.18-3 - Allow Flask-Migrate 4.x * Tue Jan 3 2023 Sandro Mani - 6.18-2 - Backport fix for CVE-2021-35065 for bundled glob-parent * Tue Jan 3 2023 Sandro Mani - 6.18-1 - Update to 6.18 - Update bundled mozjpeg (#2155769) * Thu Dec 8 2022 Sandro Mani - 6.17-2 - Fix python-azure-mgmt-rdbms-10.2.0~b5+ compatibility * Wed Dec 7 2022 Sandro Mani - 6.17-1 - Update to 6.17 * Sun Nov 27 2022 Sandro Mani - 6.16-2 - Fix incorrect path to log folder in pgadmin4-httpd * Sat Nov 19 2022 Sandro Mani - 6.16-1 - Update to 6.16 * Tue Nov 15 2022 Sandro Mani - 6.15-3 - Fix window icon on Wayland * Thu Nov 10 2022 Sandro Mani - 6.15-2 - Re-add pgadmin4_username.patch * Tue Nov 8 2022 Sandro Mani - 6.15-1 - Update to 6.15 * Tue Oct 4 2022 Sandro Mani - 6.14-2 - Re-add pgadmin4_username.patch * Fri Sep 23 2022 Sandro Mani - 6.14-1 - Update to 6.14 --------------------------------------------------------------------------------References: [ 1 ] Bug #2161638 -CVE-2023-22298 pgadmin4: Open URL Redirect Vulnerability [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2161638 [ 2 ] Bug #2163692 - CVE-2023-0241 pgadmin4: directory traversal vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2163692 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0334c6000a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade to pgadmin4-6.19 on Fedora 36 backports addresses the URL Redirect vulnerability CVE-2023-22298.. pgadmin4 update, Fedora security fix, PostgreSQL management, open source database tool. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 02, 2023 Critical Fedora
89

Fedora 37: pgAdmin 4 Upgrade FEDORA-2023-bc3f8d5b2e Moderate

Update to pgadmin4-6.19.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-e7297a4aeb 2023-01-30 01:23:29.291834 --------------------------------------------------------------------------------Name : pgadmin4 Product : Fedora 37 Version : 6.19 Release : 1.fc37 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. --------------------------------------------------------------------------------Update Information: Update to pgadmin4-6.19. --------------------------------------------------------------------------------ChangeLog: * Thu Jan 19 2023 Sandro Mani - 6.19-1 - Update to 6.19 * Wed Jan 18 2023 Benjamin A. Beasley - 6.18-3 - Allow Flask-Migrate 4.x --------------------------------------------------------------------------------References: [ 1 ] Bug #2162395 - CVE-2022-46175 pgadmin4: json5: Prototype Pollution in JSON5 via Parse Method [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2162395 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-e7297a4aeb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest pgAdmin 4 release, version 6.19, is now accessible in Fedora 37, correcting significant vulnerabilities.. pgAdmin Update,Fedora Security,PostgreSQL Tool,Open Source Administration. . LinuxSecurity.com Team

Calendar%202 Jan 30, 2023 Fedora
89

Fedora 37: FEDORA-2022-2d5a6f48e1 Critical: pgAdmin 4 Remote Code Execution

Fix compatibility with newer python-azure-mgmt-rdbms. ---- Update to pgadmin4-6.17, see https://www.pgadmin.org/docs/pgadmin4/development/release_notes_6_17.html for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-2d5a6f48e1 2022-12-18 01:39:45.530024 --------------------------------------------------------------------------------Name : pgadmin4 Product : Fedora 37 Version : 6.17 Release : 2.fc37 URL : https://www.pgadmin.org/ Summary : Administration tool for PostgreSQL Description : pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. --------------------------------------------------------------------------------Update Information: Fix compatibility with newer python-azure-mgmt-rdbms. ---- Update to pgadmin4-6.17, see https://www.pgadmin.org/docs/pgadmin4/development/release_notes_6_17.html for details. --------------------------------------------------------------------------------ChangeLog: * Thu Dec 8 2022 Sandro Mani - 6.17-2 - Fix python-azure-mgmt-rdbms-10.2.0~b5+ compatibility * Wed Dec 7 2022 Sandro Mani - 6.17-1 - Update to 6.17 --------------------------------------------------------------------------------References: [ 1 ] Bug #2151435 - CVE-2022-4223 pgadmin4: Unauthenticated remote code execution while validating the binary path [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2151435 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-2d5a6f48e1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Enhancement of pgAdmin 4 in Fedora 37, boosting alignment with python-azure-mgmt-rdbms while addressing security vulnerabilities.. pgAdmin 4 Update,Fedora Security,Python Compatibility,Fedora Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 18, 2022 Critical Fedora
89

Fedora 31: 2020-eadda524a8 Critical: phpMyAdmin XSS and SQL Injection Fixes

**Version 5.0.3** (2020-10-09) - issue #15983 Require twig ^2.9 - issue Fix option to import files locally appearing as not available - issue #16048 Fix to allow NULL as a default bit value - issue #16062 Fix "htmlspecialchars() expects parameter 1 to be string, null given" on Export xml - issue #16078 Fix no charts in monitor when using a decimal separator "," - issue #16041 Fix. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-eadda524a8 2020-10-19 17:03:39.404070 --------------------------------------------------------------------------------Name : phpMyAdmin Product : Fedora 31 Version : 5.0.3 Release : 1.fc31 URL : https://www.phpmyadmin.net/ Summary : A web interface for MySQL and MariaDB Description : phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the Web. Currently it can create and drop databases, create/drop/alter tables, delete/edit/add fields, execute any SQL statement, manage keys on fields, manage privileges,export data into various formats and is available in 50 languages --------------------------------------------------------------------------------Update Information: **Version 5.0.3** (2020-10-09) - issue #15983 Require twig ^2.9 - issue Fix option to import files locally appearing as not available - issue #16048 Fix to allow NULL as a default bit value - issue #16062 Fix "htmlspecialchars() expects parameter 1 to be string, null given" on Export xml - issue #16078 Fix no charts in monitor when using a decimal separator "," - issue #16041 Fix IN(...) clause doesn't permit multiple values on "Search" page - issue #14411 Support double tap to edit on mobile - issue #16043 Fix php error "Use of undefined constant MYSQLI_TYPE_JSON" when using the mysqlnd extension - issue #14611 Fix fatal JS error on index creation after using Enter key to submit the form - issue #16012 Set "axis-order" to swap lon and lat on MySQL > = 8.1 -issue #16104 Fixed overwriting a bookmarked query causes a PHP fatal error - issue Fix typo in a condition in the Sql class - issue #15996 Fix local setup doc links pointing to a wrong location - issue #16093 Fix error importing utf-8 with bom sql file - issue #16089 2FA UX enhancement: autofocus 2FA input - issue #16127 Fix table column description PHP error when ['DisableIS'] = true; - issue #16130 Fix local documentation links display when a PHP extension is missing -issue Fix some twig code deprecations for php 8 - issue Fix ENUM and SET display when editing procedures and functions - issue Keep full query state on "auto refresh" process list - issue Keep columns order on "auto refresh" process list - issue Fixed editing a failed query from the error message - issue #16166 Fix the alter user privileges query to make it MySQL 8.0.11+ compatible - issue Fix copy table to another database when the nbr of DBs is > $cfg['MaxDbList'] - issue #16157 Fix relations of tables having spaces or special chars not showing in the Designer - issue #16052 Fix a very rare JS error occuring on mousemove event - issue #16162 Make a foreign key link clickable in a new tab after the value was saved and replaced - issue #16163 Fixed a PHP notice "Undefined index: column_info" on views - issue #14478 Fix the data stream when exporting data in file mode - issue #16184 Fix templates/ directory not found error - issue #16184 Remove chdir logic to fix PHP fatal error "Uncaught TypeError: chdir()" - issue Support for Twig 3 - issue Allow phpmyadmin/twig-i18n-extension ^3.0 - issue #16201 Trim spaces for integer values in table search - issue #16076 Fixed cannot edit or export TIMESTAMP column with default CURRENT_TIMESTAMP in MySQL > = 8.0.13 -issue #16226 Fix error 500 after copying a table - issue #16222 Fixed can't use the search page when the table name has special characters - issue #16248 Fix zoom search is not performing input validation on INTcolumns - issue #16248 Fix javascript error when typing in INT fields on zoom search page - issue Fix type errors when using saved searches - issue #16261 Fix missing headings on modals of "User Accounts -> Export" - issue #16146 Fixed sorting did not keep the selector of number of rows - issue #16194 Fixed SQL query does not appear in case of editing view where definer is not you on MySQL 8 - issue #16255 Fix tinyint(1) shown as INT on Search page - issue #16256 Fix "Warning: error_reporting() has been disabled for security reasons" on php 7.x - issue #15367 Fix "Change or reconfigure primary server" link - issue #15367 Fix first replica links, start, stop, ignore links - issue #16058 Add "PMA_single_signon_HMAC_secret" for signon auths to make special links work and udate examples - issue #16269 Support ReCaptcha v2 checkbox width "$cfg['CaptchaMethod'] = 'checkbox';" - issue #14644 Use Doctum instead of Sami - issue #16086 Fix "Browse" headings shift when scrolling - issue #15328 Fix no message after import of zipped shapefile without php-zip - issue #14326 Fix PHP error when exporting without php-zip - issue #16318 Fix Profiling doesn't sum the number of calls - issue #16319 Fixed a Russian translation mistake on search results total text - issue #15634 Only use session_set_cookie_params once on PHP > = 7.3.0 versions for single signon auth - issue #14698 Fixed database named as 'New' (language variable) causes PHP fatal error - issue #16355 Make textareas both sides resizable - issue #16366 Fix column definition form not showing default value - issue #16342 Fixed multi-table query (db_multi_table_query.php) alias show the same alias for all columns - issue #15109 Fixed using ST_GeomFromText + GUI on insert throws an error - issue #16325 Fixed editing Geometry data throws error on using the GUI - issue [security] Fix XSS vulnerability with the transformation feature (**PMASA-2020-5, CVE-2020-26934**) - issue [security] Fix SQL injection vulnerability with searchfeature (**PMASA-2020-6, CVE-2020-26935**) --------------------------------------------------------------------------------ChangeLog: * Sat Oct 10 2020 Remi Collet - 5.0.3-1 - update to 5.0.3 (2020-10-10, security release) - raise dependency on twig 2.9 and allow v3 - allow phpmyadmin/twig-i18n-extension v3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1887249 - CVE-2020-26934 phpmyadmin: XSS relating to the transformation feature https://bugzilla.redhat.com/show_bug.cgi?id=1887249 [ 2 ] Bug #1887253 - CVE-2020-26935 phpmyadmin: SQL injection vulnerability in SearchController https://bugzilla.redhat.com/show_bug.cgi?id=1887253 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-eadda524a8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . phpMyAdmin Version 5.0.4 launched for Fedora 31 tackles security concerns such as XSS and SQL injection flaws.. phpMyAdmin Security Update, Fedora 31 phpMyAdmin, XSS Vulnerability Fix, SQL Injection Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 19, 2020 Critical Fedora
89

Fedora 31: 2019-db68ae1fca Moderate: phpMyAdmin SQL Injection Issue

Upstream announcement: **phpMyAdmin 4.9.2 is released** 2019-11-22 Welcome to phpMyAdmin 4.9.2, a bugfix release that also contains a security fix. This security fix is part of an ongoing effort to improve the security of the Designer feature and is designated **PMASA-2019-5**. There is also an improvement for how we sanitize Git version information shown on the home page,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-db68ae1fca 2019-12-01 00:45:37.366094 --------------------------------------------------------------------------------Name : phpMyAdmin Product : Fedora 31 Version : 4.9.2 Release : 1.fc31 URL : https://www.phpmyadmin.net/ Summary : Handle the administration of MySQL over the World Wide Web Description : phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the World Wide Web. Most frequently used operations are supported by the user interface (managing databases, tables, fields, relations, indexes, users, permissions), while you still have the ability to directly execute any SQL statement. Features include an intuitive web interface, support for most MySQL features (browse and drop databases, tables, views, fields and indexes, create, copy, drop, rename and alter databases, tables, fields and indexes, maintenance server, databases and tables, with proposals on server configuration, execute, edit and bookmark any SQL-statement, even batch-queries, manage MySQL users and privileges, manage stored procedures and triggers), import data from CSV and SQL, export data to various formats: CSV, SQL, XML, PDF, OpenDocument Text and Spreadsheet, Word, Excel, LATEX and others, administering multiple servers, creating PDF graphics of your database layout, creating complex queries using Query-by-example (QBE), searching globally in a database or a subset of it, transforming stored data into any format using a set of predefined functions, likedisplaying BLOB-data as image or download-link and much more... --------------------------------------------------------------------------------Update Information: Upstream announcement: **phpMyAdmin 4.9.2 is released** 2019-11-22 Welcome to phpMyAdmin 4.9.2, a bugfix release that also contains a security fix. This security fix is part of an ongoing effort to improve the security of the Designer feature and is designated **PMASA-2019-5**. There is also an improvement for how we sanitize Git version information shown on the home page, thanks to Ali Hubail. This release includes fixes for many bugs, including: * Fixes for the "Failed to set session cookie" error which relates to the cookie name. In some cases, data stored in the cookie (such as the previously-used user account) may not be loaded from a previous phpMyAdmin cookie the first time you run version 4.9.2 * Fix for Advisor with MySQL 8.0.3 and newer * Fix PHP deprecation errors * Fix a situation where exporting users after a delete query could remove users * Fix incorrect "You do not have privileges to manipulate with the users!" warning * Fix copying a database's privileges and several other problems moving columns with MariaDB * Fix for phpMyAdmin not selecting all the values when using shift-click to select during Export There are many, many more bug fixes thanks to the efforts of our developers and other contributors. The phpMyAdmin team --------------------------------------------------------------------------------ChangeLog: * Fri Nov 22 2019 Remi Collet - 4.9.2-1 - update to 4.9.2 (2019-11-22, bugfix and security release) --------------------------------------------------------------------------------References: [ 1 ] Bug #1776254 - CVE-2019-18622 phpMyAdmin: a crafted database/table name can be used to trigger an SQL injection attack through the designer feature https://bugzilla.redhat.com/show_bug.cgi?id=1776254 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-db68ae1fca' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Explore the latest phpMyAdmin version 4.9.2 update for Fedora, featuring improved security measures and bug fixes for superior web administration.. phpMyAdmin Update, MySQL Administration, Security Fix. . LinuxSecurity.com Team

Calendar%202 Nov 30, 2019 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200