Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200906-03 ] phpMyAdmin: Multiple vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Mon Jun 29, 2009 11:26 pm    Post subject: [ GLSA 200906-03 ] phpMyAdmin: Multiple vulnerabilities Reply with quote

Gentoo Linux Security Advisory

Title: phpMyAdmin: Multiple vulnerabilities (GLSA 200906-03)
Severity: high
Exploitable: remote
Date: June 29, 2009
Bug(s): #263711
ID: 200906-03

Synopsis

Multiple errors in phpMyAdmin might allow the remote execution of arbitrary code or a Cross-Site Scripting attack.

Background

phpMyAdmin is a web-based management tool for MySQL databases.

Affected Packages

Package: dev-db/phpmyadmin
Vulnerable: < 2.11.9.5
Unaffected: >= 2.11.9.5
Architectures: All supported architectures


Description

Multiple vulnerabilities have been reported in phpMyAdmin:
  • Greg Ose discovered that the setup script does not sanitize input properly, leading to the injection of arbitrary PHP code into the configuration file (CVE-2009-1151).
  • Manuel Lopez Gallego and Santiago Rodriguez Collazo reported that data from cookies used in the "Export" page is not properly sanitized (CVE-2009-1150).


Impact

A remote unauthorized attacker could exploit the first vulnerability to execute arbitrary code with the privileges of the user running phpMyAdmin and conduct Cross-Site Scripting attacks using the second vulnerability.

Workaround

Removing the "scripts/setup.php" file protects you from CVE-2009-1151.

Resolution

All phpMyAdmin users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-2.11.9.5"


References

CVE-2009-1150
CVE-2009-1151
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum