Lucene search

K
debianDebianDEBIAN:DSA-2167-1:D89AE
HistoryFeb 16, 2011 - 6:10 p.m.

[SECURITY] [DSA 2167-1] phpmyadmin security update

2011-02-1618:10:32
lists.debian.org
8

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.6

Confidence

Low

EPSS

0.043

Percentile

92.4%


Debian Security Advisory DSA-2167-1 [email protected]
http://www.debian.org/security/ Thijs Kinkhorst
February 16, 2011 http://www.debian.org/security/faq


Package : phpmyadmin
Vulnerability : sql injection
Problem type : remote
Debian-specific: no
CVE ID : CVE-2011-0987

It was discovered that phpMyAdmin, a a tool to administer MySQL over
the web, when the bookmarks feature is enabled, allowed to create a
bookmarked query which would be executed unintentionally by other users.

For the oldstable distribution (lenny), this problem has been fixed in
version 4:2.11.8.1-5+lenny8.

For the stable distribution (squeeze), this problem has been fixed in
version 4:3.3.7-5.

For the testing distribution (wheezy) and unstable distribution (sid),
this problem has been fixed in version 4:3.3.9.2-1.

We recommend that you upgrade your phpmyadmin packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: [email protected]

OSVersionArchitecturePackageVersionFilename
Debian5allphpmyadmin< 4:2.11.8.1-5+lenny8phpmyadmin_4:2.11.8.1-5+lenny8_all.deb
Debian6allphpmyadmin< 4:3.3.7-5phpmyadmin_4:3.3.7-5_all.deb

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.6

Confidence

Low

EPSS

0.043

Percentile

92.4%