Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-1918-1 Critical: phpMyAdmin XSS and SQL Injection

debian
Calendar Grey October 25, 2009
Debian Logo
Debian Security Advisory DSA-1918-1 highlights critical vulnerabilities in phpMyAdmin that may expose system integrity, urging updates to version 4.9.0 or higher
Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web

Summary

CVE-2009-3696

Cross-site scripting (XSS) vulnerability allows remote attackers to
inject arbitrary web script or HTML via a crafted MySQL table name.

CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality
allows remote attackers to execute arbitrary SQL commands. This issue
does not apply to the version in Debian 4.0 Etch.

Additionally, extra fortification has been added for the web based setup.php
script. Although the shipped web server configuration should ensure that
this script is protected, in practice this turned out not always to be the
case. The config.inc.php file is not writable anymore by the webserver user
anymore. See README.Debian for details on how to enable the setup.php
script if and when you need it.


For the old stable distribution (etch), these problems have been fixed in
version 2.9.1.1-13.

For the stable distribution (lenny), these problems have been fixed in
version 2.11.8.1-5+lenny3.

For the unstable distribution (sid), these problems ha...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here