phpMyAdmin: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201201-01 / phpMyAdmin |
| Release Date |
January 04, 2012 |
| Latest Revision |
January 04, 2012: 1 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| dev-db/phpmyadmin |
<
3.4.9 |
>=
3.4.9 |
All supported architectures
|
Related bugreports:
#302745, #335490, #336462, #354227, #373951, #376369, #387413, #389427, #395715
Synopsis
Multiple vulnerabilities were found in phpMyAdmin, the most severe
of which allows the execution of arbitrary PHP code.
2.
Impact Information
Background
phpMyAdmin is a web-based management tool for MySQL databases.
Description
Multiple vulnerabilities have been discovered in phpMyAdmin. Please
review the CVE identifiers and phpMyAdmin Security Advisories referenced
below for details.
Impact
Remote attackers might be able to insert and execute PHP code, include
and execute local PHP files, or perform Cross-Site Scripting (XSS)
attacks via various vectors.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All phpMyAdmin users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-3.4.9"
|
4.
References
|