ELA-1139-1 phppgadmin security update

remote code execution vulnerability

2024-07-25
Packagephppgadmin
Version5.1-1.1+deb8u1 (jessie)
Related CVEs CVE-2023-40619


A potential Remote Code Execution (RCE) vulnerability was discovered in phppgadmin, a web-based administration tool for the PostgreSQL database.

This was an issue related to the deserialisation of untrusted data, which may have led to remote code execution because user-controlled data was passed directly to the PHP unserialize() function.



For Debian 8 jessie, these problems have been fixed in version 5.1-1.1+deb8u1.

We recommend that you upgrade your phppgadmin packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.