| Summary: | Security issues on phpmyadmin (CVE-2019-11768 and CVE-2019-12616) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Marc Krämer <mageia> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | andrewsfarm, mageia, sysadmin-bugs, tmb |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-64-OK | ||
| Source RPM: | phpmyadmin-4.7.8-4.mga6.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 4.9.0 | ||
|
Description
Marc Krämer
2019-06-05 00:13:40 CEST
Updated phpmyadmin packages fix security vulnerabilities: A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. (PMASA-2019-3) A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) through the victim. (PMASA-2019-4) References: https://www.phpmyadmin.net/security/PMASA-2019-3/ https://www.phpmyadmin.net/security/PMASA-2019-4/ ======================== Updated packages in core/updates_testing: ======================== phpmyadmin-4.7.8-5.mga6.noarch.rpm Source RPMs: phpmyadmin-4.7.8-5.mga6.src.rpm Assignee:
mageia =>
qa-bugs These issues also affect Cauldron/Mageia 7 and need to be fixed there as well. Keywords:
(none) =>
feedback
David Walser
2019-06-05 13:03:52 CEST
Severity:
normal =>
critical already put a freeze push request for cauldron Installed and tested without issues. Normal use and some extra testing revealed no issues. System: Mageia 6, x86_64, Apache, MariaDB, Firefox, Chromium, Intel CPU. $ uname -a Linux marte 4.14.121-desktop-1.mga6 #1 SMP Wed May 22 12:26:58 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux $ rpm -q phpmyadmin apache mariadb phpmyadmin-4.7.8-5.mga6 apache-2.4.38-1.mga6 mariadb-10.1.39-1.mga6 Whiteboard:
(none) =>
MGA6-64-OK phpmyadmin-4.9.0.1-1.mga7 has been pushed in Cauldron. Thanks. Keywords:
feedback =>
(none) Validating. Advisory information in Comment 1. Keywords:
(none) =>
validated_update
Thomas Backlund
2019-06-21 02:29:38 CEST
CC:
(none) =>
tmb An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0200.html Resolution:
(none) =>
FIXED
David Walser
2019-11-26 14:15:30 CET
Summary:
Security issues on phpmyadmin =>
Security issues on phpmyadmin (CVE-2019-11768 and CVE-2019-12616) |