-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2580-1 [email protected] https://www.debian.org/lts/security/ Utkarsh Gupta March 03, 2021 https://wiki.debian.org/LTS - -----------------------------------------------------------------------
Package : adminer Version : 4.2.5-3+deb9u2 CVE ID : CVE-2021-21311 Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. For Debian 9 stretch, this problem has been fixed in version 4.2.5-3+deb9u2. We recommend that you upgrade your adminer packages. For the detailed security status of adminer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/adminer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmA+lBgACgkQgj6WdgbD S5aV8A/8C5cnxao31Xs/19/4FbLwQLlwLonNfLeEGVj8R0fHDJVAELcQk61UeHc5 CDCL8aokfTDF8Za+kPd4usZLdktcHhTZEzHYX5aCJ96iXYuK4CkB48cYZul6kBKk 9+oBBiYazANYHx426SXXr1rm/snWMCaF/yvFQ9HqZlrbNK8xKNrEOHT9/MBPIO/R iv0vbBAxfc/9vo05yChHUI7N7G7qnZHG0sFMIqkl4zcYq3C05ukyfRvNWRxQ4qUD NvzdTgzHM5c4579o8I6bQwFGdbxWIplgufbEiwNotkuarOSm6Pw6qpxR484ygCkT 2/BDLyxrLb4E/qRpkaY81kmYKVUMMWHQwzgOUkyJieT0kuPxPQjAdHik6vxG3hvk C6LqESp+HvljPeSa0eIKODyXF+Q7O66E43ebXbOTsOcZgWJlnVO51+jUQzV/0EDw 8gGPM1AiCF5phxBiK5T9ncTSMdJtzGWnywVl9VOYRtd2GGAGy9Xik/aRaafGA6Vs R5U4d5uIvNd6b5fFbBfaxlkv681IHts61dMhzzC/kZwSSuv8ADeWUmiLX/EqaiFf d+eJWYFXhSxR+DlwiCoH9Bw9EjIt+N9cl7EvhVXmLiDZiBi8cFoY+/qO6WNoumUv h/jdaf1bgPLMwwP71bg/tPsUQNsGtlxz+43BfqfEreZ+GqpeZlQ= =c2KF -----END PGP SIGNATURE-----
