phpMyAdmin: security bugs

Reindl Harald h.reindl at thelounge.net
Sat Oct 19 21:34:02 UTC 2013



Am 19.10.2013 23:26, schrieb Sérgio Basto:
> On Sáb, 2013-10-19 at 22:16 +0200, Reindl Harald wrote: 
>> Am 19.10.2013 22:04, schrieb Robert Scheck:
>>> On Wed, 09 Oct 2013, Paul Wouters wrote:
>>>> I'm not a really user of phpMyAdmin so if someone who actually uses
>>>> this package wishes to take maintainership, please do!
>>>
>>> you noticed, that you pushed yet another version of phpMyAdmin with a *.swf
>>> file that is somehow "proprietary" because we do not build the *.swf from
>>> source? I as the package maintainer of phpMyAdmin would have expected that
>>> you also are getting in touch with me at all - I can not find any e-mail in
>>> my mailbox from you... :-(
>>
>> and as user i am asking you as phpMyAdmin maintainer why are
>> you not keep the package up-to-date - they have a mailing list
>> with release announcements, however i maintain my personal one
> 
> Hi, could you post or send to me a src.rpm of your updated packaged? 

not really because it contains distributed configurations and
no longer "confignoreplace" files, but earlier in the thread
i posted my SPEC

i decided long ago to strip down the package and include our
configurations using php_uname() to have a "config.inc.php"
for all servers which behaves correctly and allows root
only from specific IP addresses


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 263 bytes
Desc: OpenPGP digital signature
URL: <http://lists.fedoraproject.org/pipermail/devel/attachments/20131019/4eacd5ef/attachment.sig>


More information about the devel mailing list