ALT-BU-2023-3156-1
Branch p10_e2k update bulletin.
Closed bugs
Package phpMyAdmin updated to version 5.2.1-alt1 for branch p10_e2k.
Closed vulnerabilities
Modified: 2025-04-01
CVE-2020-22452
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
- http://phpmyadmin.com
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
Modified: 2025-03-21
CVE-2023-25727
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-11721
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
Modified: 2024-11-21
CVE-2020-19668
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
Modified: 2024-11-21
CVE-2021-40656
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
Package color-prompt-and-man updated to version 1.2-alt1 for branch p10_e2k.
Closed bugs
Скрывает имя пользователя и цвет глаза терзает