[phpMyAdmin Developers] Security announcement: phpMyAdmin 4.8.4 is released

Isaac Bennetch <[email protected]> Tue, 11 Dec 2018 09:34:58 -0500
Newsgroups gmane.comp.php.phpmyadmin.devel
Message-ID <[email protected]>
The phpMyAdmin team announces the release of phpMyAdmin version 4.8.4.
Among other bug fixes, this contains several important security fixes.
Upgrading is highly recommended for all users.

The security fixes involve:

  * Local file inclusion
(https://www.phpmyadmin.net/security/PMASA-2018-6/),
  * XSRF/CSRF vulnerabilities allowing a specially-crafted URL to
perform harmful operations
(https://www.phpmyadmin.net/security/PMASA-2018-7/), and
  * an XSS vulnerability in the navigation tree
(https://www.phpmyadmin.net/security/PMASA-2018-8/)

In addition to the security fixes, this release also includes these bug
fixes and more as part of our regular release cycle:

  * Issue with changing theme
  * Ensure that database names with a dot ('.') are handled properly
when DisableIS is true
  * Fix for message "Error while copying database (pma__column_info)"
  * Move operation causes "SELECT * FROM `undefined`" error
  * When logging with $cfg['AuthLog'] to syslog, successful login
messages were not logged when $cfg['AuthLogSuccess'] was true
  * Multiple errors and regressions with Designer

And several more. Complete notes are in the ChangeLog file included with
this release.

Note that for this release, we experimented with a pre-release
announcement so that hosting providers and package managers would have
an opportunity to prepare for the security release. If this was helpful
to you or if you have feedback about this technique, please let us know
through the public list [email protected] or privately at
[email protected]. We may or may not decide use this behavior in
the future and your feedback will help us decide whether it's beneficial
to the community.

As always, downloads are available at https://www.phpmyadmin.net/downloads/

_______________________________________________
Developers mailing list
[email protected]
https://lists.phpmyadmin.net/mailman/listinfo/developers
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEPQalns5zDrcbURwXznUvF4JZvZIFAlwPyxMACgkQznUvF4JZ
vZLykQ//ZU7b22OvO/3mL3vMBponux3ISh//755JPQVqAzTQnxHo9PgZbT53HBYx
tVMQZP+8xYAyfYsXG1lO0Hj4iL8g5302ZHHjhjoIdSFjjOhn57MT9PtXDIaDO75O
VbXX1y24+byhiZ+hppfz+MplRX29TntSiXQe/gXg0rtldDCkXvSXz9AejEVSJLLm
lJu/brWf8fueO3YBa5jLdQyK/rmMQPB2rCzn4SkGOph4Tped9+836TSMnuIia9nK
GDHc821Jw7D87C2K87h/gPYj2spxE/RweBOXTdCZlgLicL2V/IzkVWEKAr3VuOHG
2FwGt5oaODfjrMoGdHGp8q2+fLBd264Kw1ah0npVKXrBGTLJFpIER6vsfNaPJOUk
TOuNppkHo4CGwXKy4fIxTd/trAbjzCVODfhsq9x4DfNQBzwuCTqtTfFq1I7UP50a
GUsSEGMMNvCoJmrHfvuBK3zCmBMFyIfN0SR5myCTXYA4D+fFCwm6JOnD/ic7/8H1
5KuuQd4irXNOUmjq5Ckm9qlvk0J4iFVTYfzH/YBeMhEx8GgbswUiAXYcph1KF1L4
QLKMVVJ+x7AwKZIgWlnlG5CyKjHtBupqJFgnL3niiKejRlL/T3YZFmPIUXS6JcrV
HJyrrMOBLwfquW2NpkSoGedL1w8ZTiLOSaa0z5C0c0rgeLjIQgQ=
=qVSB
-----END PGP SIGNATURE-----