Re: phpMyAdmin: security bugs

2013-10-19 Thread Robert Scheck
Hello Paul, On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take maintainership, please do! you noticed, that you pushed yet another version of phpMyAdmin with a *.swf file that is somehow proprietary because

Re: phpMyAdmin: security bugs

2013-10-19 Thread Robert Scheck
On Sat, 19 Oct 2013, Reindl Harald wrote: and as user i am asking you as phpMyAdmin maintainer why are you not keep the package up-to-date - they have a mailing list with release announcements, however i maintain my personal one It would make more sense to help *solving* the open issues rather

Re: phpMyAdmin: security bugs

2013-10-19 Thread Sérgio Basto
On Sáb, 2013-10-19 at 22:04 +0200, Robert Scheck wrote: On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take maintainership, please do! I use often and for me is an essential tool, I wish be maintainer of the

Re: phpMyAdmin: security bugs

2013-10-19 Thread Robert Scheck
Hello Sérgio, On Sat, 19 Oct 2013, Sérgio Basto wrote: I use often and for me is an essential tool, I wish be maintainer of the package , I already requested commit permissions in acls , but nothing happen until now . can you please provide any patches for review (e.g. via RHBZ) before just

Re: phpMyAdmin: security bugs

2013-10-19 Thread Robert Scheck
Hello, On Sat, 19 Oct 2013, Reindl Harald wrote: what is needed to be resolved? my SPEC file is removing all the things i do not need and not things with bugs to solve - the reason why i build it myself honestly since years is that the fedora packages are way too often outdated if you

Re: phpMyAdmin: security bugs

2013-10-19 Thread Reindl Harald
Am 19.10.2013 22:27, schrieb Robert Scheck: On Sat, 19 Oct 2013, Reindl Harald wrote: and as user i am asking you as phpMyAdmin maintainer why are you not keep the package up-to-date - they have a mailing list with release announcements, however i maintain my personal one It would make

Re: phpMyAdmin: security bugs

2013-10-19 Thread Reindl Harald
Am 19.10.2013 22:04, schrieb Robert Scheck: On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take maintainership, please do! you noticed, that you pushed yet another version of phpMyAdmin with a *.swf file

Re: phpMyAdmin: security bugs

2013-10-19 Thread Sérgio Basto
On Sáb, 2013-10-19 at 22:45 +0200, Robert Scheck wrote: Hello Sérgio, On Sat, 19 Oct 2013, Sérgio Basto wrote: I use often and for me is an essential tool, I wish be maintainer of the package , I already requested commit permissions in acls , but nothing happen until now . can you

Re: phpMyAdmin: security bugs

2013-10-19 Thread Sérgio Basto
On Sáb, 2013-10-19 at 22:16 +0200, Reindl Harald wrote: Am 19.10.2013 22:04, schrieb Robert Scheck: On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take maintainership, please do! you noticed, that you

Re: phpMyAdmin: security bugs

2013-10-19 Thread Sérgio Basto
On Sáb, 2013-10-19 at 22:23 +0100, Sérgio Basto wrote: On Sáb, 2013-10-19 at 22:45 +0200, Robert Scheck wrote: Hello Sérgio, On Sat, 19 Oct 2013, Sérgio Basto wrote: I use often and for me is an essential tool, I wish be maintainer of the package , I already requested commit

Re: phpMyAdmin: security bugs

2013-10-19 Thread Reindl Harald
Am 19.10.2013 23:26, schrieb Sérgio Basto: On Sáb, 2013-10-19 at 22:16 +0200, Reindl Harald wrote: Am 19.10.2013 22:04, schrieb Robert Scheck: On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take

Re: phpMyAdmin: security bugs

2013-10-19 Thread Robert Scheck
Hello Sérgio, On Sat, 19 Oct 2013, Sérgio Basto wrote: you already have a propose to update to 4.0.x in http://anshprat.fedorapeople.org/rhbz959946/c12/ do not only read https://bugzilla.redhat.com/show_bug.cgi?id=959946#c12 but also the other comments below - please. Greetings, Robert

Re: phpMyAdmin: security bugs

2013-10-19 Thread Paul Wouters
On Sat, 19 Oct 2013, Robert Scheck wrote: On Wed, 09 Oct 2013, Paul Wouters wrote: I'm not a really user of phpMyAdmin so if someone who actually uses this package wishes to take maintainership, please do! you noticed, that you pushed yet another version of phpMyAdmin with a *.swf file that

Re: phpMyAdmin: security bugs

2013-10-19 Thread Sérgio Basto
On Sáb, 2013-10-19 at 23:49 +0200, Robert Scheck wrote: Hello Sérgio, On Sat, 19 Oct 2013, Sérgio Basto wrote: you already have a propose to update to 4.0.x in http://anshprat.fedorapeople.org/rhbz959946/c12/ do not only read https://bugzilla.redhat.com/show_bug.cgi?id=959946#c12 but

Re: phpMyAdmin: security bugs

2013-10-09 Thread Paul Wouters
On Tue, 8 Oct 2013, Sérgio Basto wrote: 3.5.8.2 was released time ago with several bugs fixed: http://bugzilla.redhat.com/959946 Current version in Fedora Rawhide: 3.5.8.1 Welcome to phpMyAdmin 3.5.8.2, a security release. I updated all branches in fedora and epel to 3.5.8.2. These are now

phpMyAdmin: security bugs

2013-10-08 Thread Xose Vazquez Perez
hi, 3.5.8.2 was released time ago with several bugs fixed: http://bugzilla.redhat.com/959946 Current version in Fedora Rawhide: 3.5.8.1 Welcome to phpMyAdmin 3.5.8.2, a security release. 3.5.8.2 (2013-07-28) - [security] Fix self-XSS in Showing rows, see PMASA-2013-8 - [security] Fix self-XSS

Re: phpMyAdmin: security bugs

2013-10-08 Thread Sérgio Basto
On Ter, 2013-10-08 at 21:02 +0200, Xose Vazquez Perez wrote: hi, 3.5.8.2 was released time ago with several bugs fixed: http://bugzilla.redhat.com/959946 Current version in Fedora Rawhide: 3.5.8.1 Welcome to phpMyAdmin 3.5.8.2, a security release. Well bug says phpMyAdmin-4.0.8 is