SHA256
1
0
forked from pool/phpMyAdmin

Accepting request 356586 from home:AndreasStieger:branches:server:php:applications

phpMyAdmin 4.5.4

OBS-URL: https://build.opensuse.org/request/show/356586
OBS-URL: https://build.opensuse.org/package/show/server:php:applications/phpMyAdmin?expand=0&rev=247
This commit is contained in:
2016-01-28 18:21:31 +00:00
committed by Git OBS Bridge
parent 4c293924d9
commit b2d6edc01b
7 changed files with 496 additions and 7733 deletions

View File

@@ -1,3 +1,19 @@
-------------------------------------------------------------------
Thu Jan 28 18:20:05 UTC 2016 - astieger@suse.com
- phpMyAdmin 4.5.4
The followinng vulnerabilities were fixed: (boo#964024)
* CVE-2016-2038: Multiple full path disclosure vulnerabilities
* CVE-2016-2039: Unsafe generation of XSRF/CSRF token
* CVE-2016-2040: Multiple XSS vulnerabilities
* CVE-2016-1927: Insecure password generation in JavaScript
* CVE-2016-2041: Unsafe comparison of XSRF/CSRF token
* CVE-2016-2042: Multiple full path disclosure vulnerabilities
* CVE-2016-2043: XSS vulnerability in normalization page
* CVE-2016-2044: Full path disclosure vulnerability in SQL parser
* CVE-2016-2045: XSS vulnerability in SQL editor
- update upstream singing keyring
-------------------------------------------------------------------
Sun Jan 10 23:40:38 UTC 2016 - astieger@suse.com