Version in base suite: 5.2.2-really+dfsg-1 Base version: phpmyadmin_5.2.2-really+dfsg-1 Target version: phpmyadmin_5.2.2-really+dfsg-1+deb13u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/p/phpmyadmin/phpmyadmin_5.2.2-really+dfsg-1.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/p/phpmyadmin/phpmyadmin_5.2.2-really+dfsg-1+deb13u1.dsc changelog | 7 +++++++ missing-sources/jquery/jquery.validate.js | 15 ++++++++++++--- 2 files changed, 19 insertions(+), 3 deletions(-) gpgv: Signature made Tue Apr 22 18:57:26 2025 UTC gpgv: using RSA key C4D91FDFCEF6B4A3C653FD7890A0EF1B8251A889 gpgv: bad data signature from key 90A0EF1B8251A889: Wrong key usage (0x01, 0x4) gpgv: Can't check signature: Wrong key usage dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp0_5zmz8a/phpmyadmin_5.2.2-really+dfsg-1.dsc: no acceptable signature found diff: /srv/release.debian.org/tmp/hUrxhZWkaq/phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/ol/node_modules/.bin/pbf: No such file or directory diff: /srv/release.debian.org/tmp/x9eC9Qp542/phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/ol/node_modules/.bin/pbf: No such file or directory diff -Nru phpmyadmin-5.2.2-really+dfsg/debian/changelog phpmyadmin-5.2.2-really+dfsg/debian/changelog --- phpmyadmin-5.2.2-really+dfsg/debian/changelog 2025-04-19 19:06:39.000000000 +0000 +++ phpmyadmin-5.2.2-really+dfsg/debian/changelog 2025-09-04 11:51:58.000000000 +0000 @@ -1,3 +1,10 @@ +phpmyadmin (4:5.2.2-really+dfsg-1+deb13u1) trixie; urgency=medium + + * Update d/missing-source for CVE-2025-3573 - jquery-validation + - Fix XSS in the showLabel() function + + -- William Desportes Thu, 04 Sep 2025 13:51:58 +0200 + phpmyadmin (4:5.2.2-really+dfsg-1) unstable; urgency=medium [ தமிழ்நேரம் ] diff -Nru phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/jquery/jquery.validate.js phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/jquery/jquery.validate.js --- phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/jquery/jquery.validate.js 2025-04-19 18:59:43.000000000 +0000 +++ phpmyadmin-5.2.2-really+dfsg/debian/missing-sources/jquery/jquery.validate.js 2025-09-04 11:51:58.000000000 +0000 @@ -960,14 +960,23 @@ error.removeClass( this.settings.validClass ).addClass( this.settings.errorClass ); // Replace message on existing label - error.html( message ); + if ( this.settings && this.settings.escapeHtml ) { + error.text( message || "" ); + } else { + error.html( message || "" ); + } } else { // Create error element error = $( "<" + this.settings.errorElement + ">" ) .attr( "id", elementID + "-error" ) - .addClass( this.settings.errorClass ) - .html( message || "" ); + .addClass( this.settings.errorClass ); + + if ( this.settings && this.settings.escapeHtml ) { + error.text( message || "" ); + } else { + error.html( message || "" ); + } // Maintain reference to the element to be placed into the DOM place = error;