Accepting request 787358 from home:ecsos:server

- Update to 4.9.5
  This is a security release containing several bug fixes.
  * PMASA-2020-2 SQL injection vulnerability in the user accounts
    page, particularly when changing a password
  * PMASA-2020-3 SQL injection vulnerability relating to the search
    feature
  * PMASA-2020-4 SQL injection and XSS having to do with displaying
    results
  * Removing of the "options" field for the external
    transformation.

OBS-URL: https://build.opensuse.org/request/show/787358
OBS-URL: https://build.opensuse.org/package/show/server:php:applications/phpMyAdmin?expand=0&rev=347
This commit is contained in:
Eric Schirra 2020-03-23 07:52:31 +00:00 committed by Git OBS Bridge
parent 9f3e47e4c7
commit bc02fff1c5
6 changed files with 34 additions and 20 deletions

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:c3d2eb2a0a06c40f7df9ee3bfe8daaea326bdf2ebc35f83e7dfd05eb0247b6bf
size 6134852

View File

@ -1,16 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEPQalns5zDrcbURwXznUvF4JZvZIFAl4VN/QACgkQznUvF4JZ
vZLsihAAhJ65Cbv7d8jaCio2DlvUXBGrm1sEsOOC8utS4Kz4Ui6VWY98/Ra2Lz7n
tY/XOaSSDBzVRvLygwO55zK6nd/LiDn6HOfogiq1yTmqcy4ctTkSqFgGuv3pgx7G
PGadjasiQJgrczxpQHWToYgxbJPaggyhg3WsDoCasAkh06NSZobqKUSu4Gk4wTCO
9UlECby0tBdjgphu7Ot/yD5Ck/YsPCfbM2yzUiRUt2cYqOnqv5HcAyZPzHzpHdik
bhjhYJzH1jqWdsl/0lJJZRMt6yFJIH/KfiN/Zu+eCmNsa3s7wWSqXq8eAvi7ipW6
/svH+/68Gj26jKdlfzocfoDpUlzdSVpeEEU2INff+7/iU6IUp0uBZXJKX7xOvMa5
RYXsY3CMDhGqv5FsGhuDLKWQOffkxC9M++bpg8JVvr0vJceQ4caMJ82zftGA/tO0
pJjBob4zb9QZEqKMAytcLROaCC3KrqsN1kIXEu/koQaETqxbIGxxH9rCFLpNo+yT
rPKp8uZJ6dCoarQ5srFYpkhXCVKgrO2Fuz3lyOuoPK+mAtvDWXJznsPK/41xYDWQ
nMGupQyt1Ytct2nnBZIeQFK4NxM8qVAFpQ7ZPkqtRP//0p0qTiY5OP87YKsC2yTv
EEx4CDB09kV/xMf5wIkaf1xHAPTps7YZrSUyC+HnmayixjwUb3k=
=7XQt
-----END PGP SIGNATURE-----

View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:e02823e7844bc17aa6393e1acfed6970f5a3688fe8d0c693e74670d8fed9ecd4
size 6138948

View File

@ -0,0 +1,16 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEPQalns5zDrcbURwXznUvF4JZvZIFAl51k6cACgkQznUvF4JZ
vZLUtQ/+NWk7yiYvoWYiIQIMG4ZpVKDdVuoEyki+HNtckScoeQwki9acchMMJfiy
DSkYalVMYtufu17mLIaL3vDGzU9f01ucwosgcSHmsNBt/Vw3m/tsNPDq+dnFhwFw
Jmn6e91Uq+RQLzp+omCvsiWT8UveBDudP8a6iHiiOWG1pX1i/p7kbWG+f0p53yiQ
NF6qfTXpIiaTdURyxl1Bug2IKv/IpR2RCOs3fqGwiYonbS03pbuGCb8A/Kyjsktl
kde9QZcTvcOzma7neTXVnmY3wobYK6q7tEIaMEzLAdAhmlV0HjTmLmHjDJHPgVI2
NoEnDRDXNNmmDsvs3ZiXko70sDf86JAc4JSzUYCqUR2T+lpY1dej3vSZ2uzXcSXZ
RROAWTIw5zP2bktQOPTzbbjKn8hX3z9N+GYS7NvU4r1Kd+G4psCO3pdJSijwr0Ds
hRdUPD9B29WZ+PHZX3Zsl3lLzWQWKgwxyI2u8M8/L6dehhbvo/jnmKg8YuvVDnO+
DJBgBxmg8bPfAhANeDZGfnnDc8WDov9/jnRnom05FDxuQEY00xB69iKXJ0mlMrC+
7einymn6VlPJV2nLHt1uZp3ZU3oC6Lm1sdjaJcqzZlT86I97lwefZg43nsSe9Uui
jDo/UqcB0CPicYSPRdIx3RpJfETAJ5RdDZQByieBALPENuchmto=
=Lvjt
-----END PGP SIGNATURE-----

View File

@ -1,3 +1,17 @@
-------------------------------------------------------------------
Mon Mar 23 06:40:08 UTC 2020 - ecsos@opensuse.org
- Update to 4.9.5
This is a security release containing several bug fixes.
* PMASA-2020-2 SQL injection vulnerability in the user accounts
page, particularly when changing a password
* PMASA-2020-3 SQL injection vulnerability relating to the search
feature
* PMASA-2020-4 SQL injection and XSS having to do with displaying
results
* Removing of the "options" field for the external
transformation.
-------------------------------------------------------------------
Tue Jan 21 21:24:30 UTC 2020 - chris@computersalat.de

View File

@ -30,7 +30,7 @@
%define ap_grp nogroup
%endif
Name: phpMyAdmin
Version: 4.9.4
Version: 4.9.5
Release: 0
Summary: Administration of MySQL over the web
License: GPL-2.0-or-later