Name | TEMP-0987831-866E01 |
Description | SQL Server LIMIT / OFFSET SQL Injection |
Source | Automatically generated temporary name. Not for external reference. |
Debian Bugs | 987831, 987848 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
php-illuminate-database (PTS) | buster | 5.7.27-1+deb10u1 | fixed |
php-laravel-framework (PTS) | bullseye | 6.20.14+dfsg-2+deb11u1 | fixed |
bullseye (security) | 6.20.14+dfsg-2+deb11u2 | fixed | |
sid, bookworm | 8.83.26+dfsg-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
php-illuminate-database | source | buster | 5.7.27-1+deb10u1 | |||
php-illuminate-database | source | (unstable) | (unfixed) | 987848 | ||
php-laravel-framework | source | (unstable) | 6.20.14+dfsg-2 | 987831 |
https://github.com/laravel/framework/security/advisories/GHSA-4mg9-vhxq-vm7j
https://blog.laravel.com/security-sql-injection-in-sql-server-limit-offset