forked from pool/phpMyAdmin
Accepting request 356586 from home:AndreasStieger:branches:server:php:applications
phpMyAdmin 4.5.4 OBS-URL: https://build.opensuse.org/request/show/356586 OBS-URL: https://build.opensuse.org/package/show/server:php:applications/phpMyAdmin?expand=0&rev=247
This commit is contained in:
@@ -1,3 +1,19 @@
|
||||
-------------------------------------------------------------------
|
||||
Thu Jan 28 18:20:05 UTC 2016 - astieger@suse.com
|
||||
|
||||
- phpMyAdmin 4.5.4
|
||||
The followinng vulnerabilities were fixed: (boo#964024)
|
||||
* CVE-2016-2038: Multiple full path disclosure vulnerabilities
|
||||
* CVE-2016-2039: Unsafe generation of XSRF/CSRF token
|
||||
* CVE-2016-2040: Multiple XSS vulnerabilities
|
||||
* CVE-2016-1927: Insecure password generation in JavaScript
|
||||
* CVE-2016-2041: Unsafe comparison of XSRF/CSRF token
|
||||
* CVE-2016-2042: Multiple full path disclosure vulnerabilities
|
||||
* CVE-2016-2043: XSS vulnerability in normalization page
|
||||
* CVE-2016-2044: Full path disclosure vulnerability in SQL parser
|
||||
* CVE-2016-2045: XSS vulnerability in SQL editor
|
||||
- update upstream singing keyring
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Sun Jan 10 23:40:38 UTC 2016 - astieger@suse.com
|
||||
|
||||
|
Reference in New Issue
Block a user