openSUSE-SU-2019:0194-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0194-1
openSUSE-SU-2019:0194-1
Summary: Security update for phpMyAdmin
Details: This update for phpMyAdmin to version 4.8.5 fixes the following issues: Security issues fixed: - CVE-2019-6799: Fixed an arbitrary file read vulnerability (boo#1123272) - CVE-2019-6798: Fixed a SQL injection in the designer interface (boo#1123271) Other changes: * Fix rxport to SQL format not available * Fix QR code not shown when adding two-factor authentication to a user account * Fix issue with adding a new user in MySQL 8.0.11 and newer * Fix frozen interface relating to Text_Plain_Sql plugin * Fix missing table level operations tab
References: https://lists.opensuse.org/archives/list/[email protected]/thread/AUV4H47SLYAJV3ZDW2UOJQWF7VJAKJNU/#AUV4H47SLYAJV3ZDW2UOJQWF7VJAKJNU, https://bugzilla.suse.com/1123271, https://bugzilla.suse.com/1123272, https://www.suse.com/security/cve/CVE-2019-6798, https://www.suse.com/security/cve/CVE-2019-6799
Affected packages
Package
Name: phpMyAdmin
Purl: pkg:rpm/suse/phpMyAdmin&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
