On Wed, Nov 02, 2005 at 06:42:16PM +0100, Simon Paillard wrote: > Je joins le correctif pour la VO (s'il est appliqué à toutes les > langues, il faudrait passer la version dans l'entête de la VF). > > Merci d'avance pour vos relectures.
Le même avec un correctif de la vo bien balisé. -- Simon Paillard
<define-tag description>several vulnerabilities</define-tag> <define-tag moreinfo> <p>Several cross-site scripting vulnerabilities have been discovered in phpmyadmin, a set of PHP-scripts to administrate MySQL over the WWW. The Common Vulnerabilities and Exposures project identifies the following problems:</p> <ul> <li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2869">CAN-2005-2869</li> <p>Andreas Kerber and Michal Cihar discovered several cross-site scripting vulnerabilities in the error page and in the cookie login.</p></li> <li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3300">CVE-2005-3300</li> <p>Stefan Esser discovered missing safety checks in grab_globals.php that could allow an attacker to induce phpmyadmin to include an arbitrary local file.</p></li> <li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3301">CVE-2005-3301</li> <p>Tobias Klein discovered several cross-site scripting vulnerabilities that could allow attackers to inject arbitrary HTML or client-side scripting.</p></li> </ul> <p>The version in the old stable distribution (woody) has probably its own flaws and is not easily fixable without a full audit and patch session. The easier way is to upgrade it from woody to sarge.</p> <p>For the stable distribution (sarge) these problems have been fixed in version 2.6.2-3sarge1.</p> <p>For the unstable distribution (sid) these problems have been fixed in version 2.6.4-pl1-1.</p> <p>We recommend that you upgrade your phpmyadmin package.</p> </define-tag> # do not modify the following line #include "$(ENGLISHDIR)/security/2005/dsa-880.data" # $Id: dsa-880.wml,v 1.1 2005/11/02 11:14:36 joey Exp $