Bug#980899: php-illuminate-database: CVE-2021-21263 Query Binding Exploitation

2021-05-01 Thread Robin Gustafsson
Control: tags -1 patch Hi, I've backported upstream's fixes for version 6.x. to version 5.7, along with a few additional lines that I believe are required to adequately fix this for 5.7. This seems to work as far as I can tell; upstream's test suite shows no regressions and the tests they added

Bug#980899: [pkg-php-pear] Bug#980899: php-illuminate-database: CVE-2021-21263 Query Binding Exploitation

2021-02-14 Thread David Prévot
Control: reassign -1 src:php-illuminate-database I filled the bug against the binary package, that has been superseded by src:php-laravel-framework and thus missed the expected audience, sorry about that. Le Tue, Feb 02, 2021 at 11:20:06AM -0400, David Prévot a écrit : > Le 23/01/2021 à 18:49,

Bug#980899: [pkg-php-pear] Bug#980899: php-illuminate-database: CVE-2021-21263 Query Binding Exploitation

2021-02-02 Thread David Prévot
Le 23/01/2021 à 18:49, David Prévot a écrit : Package: php-illuminate-database Version: 5.7.27-1 […] A quick look at the php-illuminate-database code, as shipped in stable, makes me think that it is probably vulnerable to CVE-2021-21263 as fixed in 6.20.11 Also, since the CVE-2021-21263 fix

Bug#980899: php-illuminate-database: CVE-2021-21263 Query Binding Exploitation

2021-01-23 Thread David Prévot
Package: php-illuminate-database Version: 5.7.27-1 Severity: important Tags: security upstream X-Debbugs-Cc: Robin Gustafsson , Debian Security Team Hi, A quick look at the php-illuminate-database code, as shipped in stable, makes me think that it is probably vulnerable to CVE-2021-21263 as