Re: phpmyadmin / CVE-2018-19968

2018-12-17 Thread Brian May
Sorry, somehow stuffed up the subject line. Meant to reference CVE-2018-19968. -- Brian May

phpmyadmin / CVE-2016-5739.patch

2018-12-17 Thread Brian May
Ok, so as far as I can tell, looking at the version in wheezy, the problem is that we load source files like so (there are two occurances in the code that I can see, both very similar): include_once $include_file; Where include_file comes from: $file = $mime_map[$meta->name]['transformation']; $

Re: MySQL 5.5 EOL before Debian 8 LTS ends

2018-12-17 Thread Norvald H. Ryeng
On Mon, 17 Dec 2018 10:49:57 +0100 Emilio Pozuelo Monfort wrote: > MySQL 5.5 should be EOL this month if nothing has changed, although I > don't see an announcement on [1] yet. Maybe it will be published next > month when the next CPU (critical patch update) is released. Norvald, > do you know if

Re: Possible patch-backport problem for libphp-phpmailer (DLA-1591-1)

2018-12-17 Thread Emilio Pozuelo Monfort
On 12/12/2018 04:56, Abhijith PA wrote: > Hi. > > On Tuesday 11 December 2018 12:59 PM, Chris Lamb wrote: >> Hi Salvatore. >> >>> While preparing an update for libphp-phpmailer I noticed in the >>> patch/diff for DLA-1591-1 for libphp-phpmailer the following: >> >> Thanks for flagging. I will try

Re: MySQL 5.5 EOL before Debian 8 LTS ends

2018-12-17 Thread Emilio Pozuelo Monfort
Hi, On 22/05/2018 07:10, Lars Tangvald wrote: > > > On 05/21/2018 03:22 PM, Matus UHLAR - fantomas wrote: Am 22.01.2018 um 13:42 schrieb Lars Tangvald: > First off, thanks for handling the 5.5.59 update for Wheezy. I had the > security announcement date mixed up so picked it up too