Executive Summary
| Summary | |
|---|---|
| Title | New phpmyadmin packages fix several vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | DSA-2097 | First vendor Publication | 2010-08-29 |
| Vendor | Debian | Last vendor Modification | 2010-09-11 |
| Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
The update in DSA 2097 for phpMyAdmin did not correctly apply the intended changes, thereby not completely addressing the vulnerabilities. Updated packages now fix the issues described in the original advisory text below. Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3055 The configuration setup script does not properly sanitise its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. In Debian, the setup tool is protected through Apache HTTP basic authentication by default. CVE-2010-3056 Various cross site scripting issues have been discovered that allow a remote attacker to inject arbitrary web script or HTML. For the stable distribution (lenny), these problems have been fixed in version 2.11.8.1-5+lenny6. For the testing (squeeze) and unstable distribution (sid), these problems have been fixed in version 3.3.5.1-1. We recommend that you upgrade your phpmyadmin package. |
Original Source
| Url : http://www.debian.org/security/2010/dsa-2097 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls |
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 67491 | phpMyAdmin libraries/sqlparser.lib.php Unspecified Parameter XSS |
| 67490 | phpMyAdmin libraries/sanitizing.lib.php Unspecified Parameter XSS |
| 67489 | phpMyAdmin libraries/db_info.inc.php Unspecified Parameter XSS |
| 67488 | phpMyAdmin libraries/dbi/mysqli.dbi.lib.php Unspecified Parameter XSS |
| 67487 | phpMyAdmin libraries/dbi/mysql.dbi.lib.php Unspecified Parameter XSS |
| 67486 | phpMyAdmin libraries/database_interface.lib.php Unspecified Parameter XSS |
| 67485 | phpMyAdmin libraries/common.lib.php Unspecified Parameter XSS |
| 67343 | phpMyAdmin Extension for TYPO3 Multiple Unspecified XSS |
| 67325 | phpMyAdmin tbl_sql.php Unspecified Parameter XSS |
| 67324 | phpMyAdmin tbl_replace.php fields[multi_edit][] Parameter XSS |
| 67323 | phpMyAdmin sql.php Multiple Parameter XSS |
| 67322 | phpMyAdmin setup/config.php DefaultLang Parameter XSS |
| 67321 | phpMyAdmin server_privileges.php Multiple Parameter XSS |
| 67320 | phpMyAdmin server_databases.php sort_by Parameter XSS |
| 67319 | phpMyAdmin js/messages.php db Parameter XSS |
| 67318 | phpMyAdmin db_structure.php sort Parameter XSS |
| 67317 | phpMyAdmin db_sql.php delimiter Parameter XSS |
| 67316 | phpMyAdmin db_search.php field_str Parameter XSS |
| 67310 | phpMyAdmin setup.php Configuration File Arbitrary PHP Code Injection |

DSA-2097
(High)
(Medium)





