Bug 26036 - phpmyadmin new security issue CVE-2020-5504
Summary: phpmyadmin new security issue CVE-2020-5504
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-01-08 15:17 CET by David Walser
Modified: 2020-01-12 00:53 CET (History)
3 users (show)

See Also:
Source RPM: phpmyadmin-4.9.3-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-01-08 15:17:42 CET
phpMyAdmin 4.9.4 has been released today (January 8), fixing some regressions in the last update as well as a new security issue:
https://www.phpmyadmin.net/news/2020/1/8/phpmyadmin-494-and-501-are-released/
https://www.phpmyadmin.net/security/PMASA-2020-1/
Comment 1 Marc Krämer 2020-01-08 20:05:16 CET
Updated phpmyadmin package fix security vulnerability:

A SQL injection flaw has been discovered in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

References:
https://www.phpmyadmin.net/news/2020/1/8/phpmyadmin-494-and-501-are-released/
https://www.phpmyadmin.net/security/PMASA-2020-1/
========================

Updated packages in core/updates_testing:
========================
phpmyadmin-4.9.4-1.mga7.noarch.rpm

Source RPMs: 
phpmyadmin-4.9.4-1.mga7.src.rpm

Assignee: mageia => qa-bugs

Comment 2 PC LX 2020-01-09 13:05:11 CET
Installed and tested without issues.


Tested local and remote servers. No regressions.


System: Mageia 7, x86_64, Apache, MariaDB, Firefox, Chromium, Intel CPU.


$ uname -a
Linux marte 5.4.6-desktop-2.mga7 #1 SMP Mon Dec 23 12:05:27 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -q phpmyadmin apache mariadb
phpmyadmin-4.9.4-1.mga7
apache-2.4.41-1.2.mga7
mariadb-10.3.20-1.mga7

CC: (none) => mageia

PC LX 2020-01-09 13:05:42 CET

Whiteboard: (none) => MGA7-64-OK

Thomas Backlund 2020-01-11 23:39:48 CET

Keywords: (none) => advisory, validated_update
CC: (none) => tmb, sysadmin-bugs

Comment 3 Mageia Robot 2020-01-12 00:53:41 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0033.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.