Debian Security Advisory DSA 759-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
July 18th, 2005 http://www.debian.org/security/faq

Package : phppgadmin
Vulnerability : missing input sanitising
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2005-2256
BugTraq ID : 14142

A vulnerability has been discovered in phppgadmin, a set of PHP scripts to administrate PostgreSQL over the WWW, that can lead to disclose sensitive information. Successful exploitation requires that "magic_quotes_gpc" is disabled.

the old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 3.5.2-5.

For the unstable distribution (sid) this problem has been fixed in version 3.5.4.

We recommend that you upgrade your phppgadmin package.

Debian GNU/Linux 3.1 alias sarge

