~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2016-7405

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2016-7405
2
 
PublicDate: 2016-10-03
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7405
5
 
 https://github.com/ADOdb/ADOdb/issues/226
6
 
 https://github.com/ADOdb/ADOdb/commit/bd9eca9
7
 
 http://www.openwall.com/lists/oss-security/2016/09/07/8
8
 
Description:
9
 
 The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x
10
 
 before 5.20.7 might allow remote attackers to conduct SQL injection attacks
11
 
 via vectors related to incorrect quoting.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=837211
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_libphp-adodb:
21
 
upstream_libphp-adodb: released (5.20.6-1)
22
 
precise_libphp-adodb: ignored (reached end-of-life)
23
 
precise/esm_libphp-adodb: DNE (precise was needed)
24
 
trusty_libphp-adodb: needed
25
 
vivid/stable-phone-overlay_libphp-adodb: DNE
26
 
vivid/ubuntu-core_libphp-adodb: DNE
27
 
xenial_libphp-adodb: needed
28
 
yakkety_libphp-adodb: ignored (reached end-of-life)
29
 
zesty_libphp-adodb: ignored (reached end-of-life)
30
 
artful_libphp-adodb: needed
31
 
bionic_libphp-adodb: needed
32
 
devel_libphp-adodb: needed