Bug 230328

Summary: PMASA-2007-3: phpMyAdmin 2.10.0.2 is released
Product: [Fedora] Fedora Reporter: Robert Scheck <redhat-bugzilla>
Component: phpMyAdminAssignee: Mike McGrath <mmcgrath>
Status: CLOSED NEXTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: medium    
Version: rawhideCC: redhat-bugzilla
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-03-05 02:23:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Robert Scheck 2007-02-28 12:18:57 UTC
Description of problem:
The phpMyAdmin Project announces the immediate availability of phpMyAdmin 
2.10.0.

Version-Release number of selected component (if applicable):
phpMyAdmin-2.9.2-1

Expected results:
Upgrade to 2.10.0 ;-)

Comment 1 Robert Scheck 2007-03-04 13:10:04 UTC
phpMyAdmin 2.10.0.1 is released
This version contains just one change from 2.10.0: a default value of false for 
$cfg['Servers'][$i]['ssl']. The default value of true is problematic on some 
servers.

phpMyAdmin 2.10.0.2 is released
The "Month Of PHP Bugs" reveals some PHP vulnerabilities. MOPB-02-2007 (PHP 
Executor Deep Recursion Stack Overflow) uses phpMyAdmin as an example to show a 
recursion vulnerability in PHP, for which a workaround is provided in version 
2.10.0.2. More details will follow on phpmyadmin.net, Security section, PMASA-
2007-3: http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3

Comment 2 Mike McGrath 2007-03-05 02:23:59 UTC
Built, should be on the mirrors soon.