- Package:
- src:adminer
- Source:
- src:adminer
- Submitter:
- Moritz Mühlenhoff
- Date:
- 2024-07-31 20:57:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for adminer. CVE-2023-45196[0]: | Adminer and AdminerEvo allow an unauthenticated remote attacker to | cause a denial of service by connecting to an attacker-controlled | service that responds with HTTP redirects. The denial of service is | subject to PHP configuration limits. Adminer is no longer supported, | but this issue was fixed in AdminerEvo version 4.8.4. https://github.com/adminerevo/adminerevo/pull/102/commits/23e7cdc0a32b3739e13d19ae504be0fe215142b6 CVE-2023-45195[1]: | Adminer and AdminerEvo are vulnerable to SSRF via database | connection fields. This could allow an unauthenticated remote | attacker to enumerate or access systems the attacker would not | otherwise have access to. Adminer is no longer supported, but this | issue was fixed in AdminerEvo version 4.8.4. https://github.com/adminerevo/adminerevo/pull/102/commits/18f3167bbcbec3bc746f62db72e016aa99144efc It seems adminer is dead upstream and adminerevo picked up development, so most likely Debian should follow the new upstream? If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-45196 https://www.cve.org/CVERecord?id=CVE-2023-45196 [1] https://security-tracker.debian.org/tracker/CVE-2023-45195 https://www.cve.org/CVERecord?id=CVE-2023-45195 Please adjust the affected versions in the BTS as needed.
Hi, Thanks a lot for reporting, I should have seen that. I have not been able to find[1] a sponsor for adminerevo although the packaging as a separate source package is done. I can easily switch src:adminer to use adminerevo source as I have DM upload rights for adminer, but that is not what I have been instructed to do. Regarding the present bug report, I'll backport the fixes in the coming days. [1] https://bugs.debian.org/1065534 Thanks, Alex
Hi, Actually I don't have DM upload rights for adminer. So the fixed package is awaiting sponsorship: https://mentors.debian.net/package/adminer/ Thanks, Alex
close 1074430 4.8.1-4 thanks