SB2013110411 - Gentoo update for phpMyAdmin



SB2013110411 - Gentoo update for phpMyAdmin

Published: November 4, 2013 Updated: September 25, 2016

Security Bulletin ID SB2013110411
Severity
Medium
Patch available
YES
Number of vulnerabilities 13
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 31% Low 69%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 13 secuirty vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2013-1937)

Vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability is caused by an input validation error in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might when processing the (1) visualizationSettings. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


2) Input validation error (CVE-ID: CVE-2013-3238)

The vulnerability allows a remote #AU# to read and manipulate data.

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /ex00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.


3) Code Injection (CVE-ID: CVE-2013-3239)

The vulnerability allows a remote #AU# to read and manipulate data.

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.


4) Cross-site scripting (CVE-ID: CVE-2013-4995)

Vulnerability allows a remote attacker to perform Cross-site scripting attacks.

An input validation error exists in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


5) Cross-site scripting (CVE-ID: CVE-2013-4996)

Vulnerability allows a remote attacker to perform Cross-site scripting attacks.

An input validation error exists in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 when processing vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


6) Cross-site scripting (CVE-ID: CVE-2013-4997)

Vulnerability allows a remote attacker to perform Cross-site scripting attacks.

An input validation error exists in phpMyAdmin 3.5.x before 3.5.8.2 when processing vectors involving a JavaScript event in (1) an anchor identifier to setup/index.php or (2) a chartTitle (aka chart title) value. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


7) Information disclosure (CVE-ID: CVE-2013-4998)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.


8) Information disclosure (CVE-ID: CVE-2013-4999)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.


9) Information disclosure (CVE-ID: CVE-2013-5000)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.


10) Cross-site scripting (CVE-ID: CVE-2013-5001)

Vulnerability allows a remote attacker to perform Cross-site scripting attacks.

An input validation error exists in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


11) Cross-site scripting (CVE-ID: CVE-2013-5002)

Vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability is caused by an input validation error in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


12) SQL injection (CVE-ID: CVE-2013-5003)

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.


13) Input validation error (CVE-ID: CVE-2013-5029)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.


Remediation

Install update from vendor's website.