phpMyAdmin Security fixes in versions 3.3.10.2 and 3.4.3.1

Bug #806788 reported by William Van Hevelingen
272
This bug affects 2 people
Affects Status Importance Assigned to Milestone
phpmyadmin (Ubuntu)
Invalid
Undecided
Micah Gersten
Lucid
Invalid
Undecided
xenol
Maverick
Invalid
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned
visibility: private → public
Revision history for this message
Micah Gersten (micahg) wrote :

Filed sync bug #807086 for oneiric

Changed in phpmyadmin (Ubuntu):
assignee: nobody → Micah Gersten (micahg)
status: New → In Progress
Changed in phpmyadmin (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
xenol (xenol) wrote :

Hello,

I created debdiff with upstream patches applied. I tried to follow standard package howto. I would like to have the debdiff reviewed. If it is correct, I would like developers to apply it and push it to the repositories, so we can have fixes.

If something is wrong, please let me know, so I can fix it. After getting the patch into repository, I will post another patch for hardy release.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Hi,

Thanks for the debdiff, but since that package uses a patch system, you need to separate the different security fixes into separate patches with proper tags that point to the patches origin.

See https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Packaging for more information.

Unsubscribing ubuntu-security-sponsors for now. Please subscribe ubuntu-security-sponsors again once you've attached an updated debdiff.

Thanks!

Revision history for this message
xenol (xenol) wrote :
Changed in phpmyadmin (Ubuntu Maverick):
status: New → Incomplete
Changed in phpmyadmin (Ubuntu Natty):
status: New → Incomplete
Changed in phpmyadmin (Ubuntu Lucid):
status: New → Triaged
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for the updated debdiff. Unfortunately, it does not follow the guidelines in https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Packaging:
 * the version number is incorrect
 * the changelog references 'NMU'. We don't have 'maintainers' in Ubuntu so this can be omitted
 * the distribution name is 'unstable'. It should be 'lucid-security'
 * the changelog text is too wide. It should not be wider than 80 characters
 * because the packaging uses a patch system, the patches should use DEP-3 comments with a minimum of 'Origin', 'Description' and 'Bug-Ubuntu' (but others are fine to include)
 * the debdiff includes debian/patches/debian-changes-4:3.3.2-2. This should be broken out into separate patches with DEP-3 appropriate DEP-3 comments
 * the changelog date should be updated
 * the changelog uses '(closes: #806788)', but should instead use '(LP: #806788)'

Unsubscribing ubuntu-security-sponsors for now. Please subscribe ubuntu-security-sponsors again once you've attached an updated debdiff.

Thanks!

Changed in phpmyadmin (Ubuntu Lucid):
assignee: nobody → xenol (xenol)
status: Triaged → Incomplete
tags: added: patch-needswork
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

We are closing this bug report because it lacks the information we need to investigate the problem, as described in the previous comments. Please reopen it if you can give us the missing information, and don't hesitate to submit bug reports in the future. To reopen the bug report you can click on the current status, under the Status column, and change the Status back to 'New'. Thanks again!

Changed in phpmyadmin (Ubuntu):
status: Fix Released → Invalid
Changed in phpmyadmin (Ubuntu Lucid):
status: Incomplete → Invalid
Changed in phpmyadmin (Ubuntu Maverick):
status: Incomplete → Invalid
Changed in phpmyadmin (Ubuntu Natty):
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.