[SECURITY] Fedora 17 Update: phpMyAdmin-3.5.0-1.fc17

updates at fedoraproject.org updates at fedoraproject.org
Wed May 2 04:49:15 UTC 2012

Fedora Update Notification
2012-04-10 20:09:04

Name        : phpMyAdmin
Product     : Fedora 17
Version     : 3.5.0
Release     : 1.fc17
URL         : http://www.phpmyadmin.net/
Summary     : Handle the administration of MySQL over the World Wide Web
Description :
phpMyAdmin is a tool written in PHP intended to handle the administration of
MySQL over the World Wide Web. Most frequently used operations are supported
by the user interface (managing databases, tables, fields, relations, indexes,
users, permissions), while you still have the ability to directly execute any
SQL statement.

Features include an intuitive web interface, support for most MySQL features
(browse and drop databases, tables, views, fields and indexes, create, copy,
drop, rename and alter databases, tables, fields and indexes, maintenance
server, databases and tables, with proposals on server configuration, execute,
edit and bookmark any SQL-statement, even batch-queries, manage MySQL users
and privileges, manage stored procedures and triggers), import data from CSV
and SQL, export data to various formats: CSV, SQL, XML, PDF, OpenDocument Text
and Spreadsheet, Word, Excel, LATEX and others, administering multiple servers,
creating PDF graphics of your database layout, creating complex queries using
Query-by-example (QBE), searching globally in a database or a subset of it,
transforming stored data into any format using a set of predefined functions,
like displaying BLOB-data as image or download-link and much more...

Update Information:

Changes for (2012-04-07):

- [interface] Add support for mass prefix change.
- [display] "up to date" message on main page when current version is up to date
- [feature] Update to jQuery 1.6.2
- [search] Show/hide db search results
- [patch] Add gettext wrappers around a message
- [cleanup] Remove deprecated function PMA_DBI_get_fields
- [feature] Remember recent tables
- [feature] Remember the last sort order for each table
- [ajax] for Create table in navigation panel
- [feature] Wording about Column
- [ajax] AJAX for Add a user in Database privileges
- [feature] new DisableMultiTableMaintenance directive
- [interface] Reorganised server status page.
- [interface] Changed way of generating charts.
- [interface] Flexible column width
- [interface] Mouse-based column reordering in query results
- [ajax] AJAX for Insert to a table from database Structure page
- [patch] PMA_ajaxShowMessage() does not respect timeout
- [ajax] AJAX for Change on multiple rows in table Browse
- [interface] Improved support for stored routines
- [display] More options for browsing GIS data
- [interface] Support for spatial indexes
- [display] GIS data visualization
- [ajax] AJAX for table structure multiple-column change
- [ajax] AJAX for table structure index edit
- [feature] Show/hide indexes in table Structure
- [display] More compact navigation bar
- [display] Display direction (horizontal/vertical) no longer displayed by default
- [feature] Shift/click support in database Structure
- [display] Show/hide column in table Browse
- [ajax] AJAX dialogs use wrong font-size
- [interface] Timepicker does not work in AJAX dialogs
- [ajax] AJAX for table Structure Indexes Edit
- [ajax] AJAX for table Structure column Change
- [interface] Improved support for events
- [interface] Improved support for triggers
- [interface] Improved server monitoring
- [ajax] AJAX for table Structure column Add
- [ajax] AJAX for table Operations copy table
- [export] no uid Query result export (Suhosin limit)
- [feature] Grid editing in browse mode (replaces row inline edit)
- [feature] Zoom-search in table Search
- [interface] Editor for GIS data
- [import] Import GIS data from ESRI Shapefiles
- [interface] 'Function based search' for GIS data
- [database] Support Drizzle database
- [interface] Interface problems for queries having LIMIT clauses
- [interface] Remove DefaultPropDisplay feature
- [prettyprint] Order By in a query containing comment character
- [interface] Improved ENUM/SET editor
- [pmadb] pmadb on a different MySQL server
- [interface] Improving field size for character columns
- [usability] Removed an unnecessary AJAX request from database search
- [navi] Tabs break when squeezing page
- [navi] Stick table tools to top of page on scroll
- [interface] Improved error handling
- [interface] Add useful intermediate pages to pageselector
- [interface] Improved index editor
- [display] View editing via a generated ALTER VIEW
- [interface] Deleting table from the DB does not change the table counter
- [designer] Toggle for relation lines
- [ajax] database list not updated after adding/deleting a user + database
- [edit] Sort by key generates wrong sql with limit clause
- [structure] Error dropping index of non-existing column
- [display] Page through rows returned from a view
- [interface] Checkbox to have SQL input remain
- [export] Fixed CSV escape for the export
- [import] Fixed CSV escape for the import
- [interface] No warning on syntax error in search form 
- [core] Improved detection of SSL connection
- [feature] FULLTEXT support for InnoDB, starting with MySQL 5.6.4
- [interface] Duplicate inline query edit box
- [mime] Description of the transformation missing in the tooltip 

Changes for (not yet released):
- [import] Exception on XML import
- [navi] $cfg['ShowTooltipAliasTB'] and blank names in navigation

Changes for (2012-03-28):
- [security] Fixed local path disclosure vulnerability, see PMASA-2012-2

Changes for (2012-02-18):
- [security] XSS in replication setup, see PMASA-2012-1

Changes for (2012-02-14):
- [interface] TextareaAutoSelect feature broken
- [export] PHP Array export might generate invalid php code
- [import] Import from ODS ignores cell that is the same as cell before
- [display] SELECT DISTINCT displays wrong total records found
- [operations] copy table data missing SET SQL_MODE='NO_AUTO_VALUE_ON_ZERO'
- [edit] Setting data to NULL and drop-downs
- [edit] Missing set fields and values in generated INSERT query
- [libraries] license issue with TCPDF (updated to 5.9.145)

  [ 1 ] Bug #795020 - CVE-2012-1190 phpMyAdmin: XSS in replication setup (PMASA-2012-1)
  [ 2 ] Bug #809146 - CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2)

This update can be installed with the "yum" update program.  Use 
su -c 'yum update phpMyAdmin' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at

More information about the package-announce mailing list