Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.rc > #358000

Bug#1053004: CVE-2019-10784 and CVE-2023-40619

From Leandro Cunha <leandrocunha016@gmail.com>
Newsgroups linux.debian.bugs.rc
Subject Bug#1053004: CVE-2019-10784 and CVE-2023-40619
Date 2024-03-06 04:40 +0100
Message-ID <IeQil-eIBS-1@gated-at.bofh.it> (permalink)
References <Hz0qZ-4Ixx-5@gated-at.bofh.it> <Hinai-bL1x-9@gated-at.bofh.it> <Hz0qZ-4Ixx-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi,

On Sat, Nov 11, 2023 at 2:53 PM Leandro Cunha <leandrocunha016@gmail.com> wrote:
>
> Hi,
>
> According to a survey carried out, it was found that the OpenSUSE
> people resolved these CVEs and started distributing the fork
> https://github.com/ReimuHakurei/phpPgAdmin. According to the links
> below:
> https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4YEBNCIRQOKETS4R7J5GXRP3TKF2YKFJ/
> https://build.opensuse.org/request/show/1123216
>
> I'm working on doing the same for Debian, currently testing and
> reviewing the package. At the same time, the libphp-adodb package will
> receive an NMU to be compatible with PHP 8.2 according to the website
> https://adodb.org/dokuwiki/doku.php?id=v5:php_compatibility_status and
> https://bugs.debian.org/ cgi-bin/bugreport.cgi?bug=1053525.
>
> --
> Cheers,
> Leandro Cunha

Just to add that in addition to OpenSUSE Tumbleweed and Leap
15.5/15.6, we have FreeBSD, AUR and Gentoo currently distributing this
package from the same source as can be seen in the links below. The
next job would be to make it available through backports and I would
choose to remove this package from stable. But I would only leave
bookworm backports due to other bugs found (this CVEs too) and fixed
in 7.14.7.
I have to search about the status of backports to oldstable. But I'm
also studying the possibility of working with patches for these two
versions.

[1] https://repology.org/project/phppgadmin/versions
[2] https://software.opensuse.org/package/phpPgAdmin
[3] https://build.opensuse.org/package/show/home%3Aecsos%3Aserver/phpPgAdmin
[4] https://build.opensuse.org/package/show/openSUSE%3AFactory/phpPgAdmin
[5] https://www.freshports.org/databases/phppgadmin
[6] https://packages.gentoo.org/packages/dev-db/phppgadmin

-- 
Cheers,
Leandro Cunha

Back to linux.debian.bugs.rc | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Bug#1053004: CVE-2019-10784 and CVE-2023-40619 Leandro Cunha <leandrocunha016@gmail.com> - 2023-11-11 19:00 +0100
  Bug#1053004: CVE-2019-10784 and CVE-2023-40619 Leandro Cunha <leandrocunha016@gmail.com> - 2024-03-06 04:40 +0100

csiph-web