Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian: DSA-3627-1 Critical: phpMyAdmin XSS Issues Resolved

debian
Calendar Grey July 24, 2016
Debian Logo
A number of security flaws in phpMyAdmin have been highlighted in Debian Security Advisory DSA-3627-1. It is advised to perform an upgrade.
Several vulnerabilities have been fixed in phpMyAdmin, the web-based MySQL administration interface

Summary

CVE-2016-1927

The suggestPassword function relied on a non-secure random number
generator which makes it easier for remote attackers to guess
generated passwords via a brute-force approach.

CVE-2016-2039

CSRF token values were generated by a non-secure random number
genrator, which allows remote attackers to bypass intended access
restrictions by predicting a value.

CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities allow remote
authenticated users to inject arbitrary web script or HTML.

CVE-2016-2041

phpMyAdmin does not use a constant-time algorithm for comparing
CSRF tokens, which makes it easier for remote attackers to bypass
intended access restrictions by measuring time differences.

CVE-2016-2560

Multiple cross-site scripting (XSS) vulnerabilities allow remote
attackers to inject arbitrary web script or HTML.

CVE-2016-2561

Multiple cross-site scripting (XSS) vulnerabilities allow remote
attackers to inject arbitrary web scr...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: phpmyadmin
CVE ID: CVE-2016-1927 CVE-2016-2039 CVE-2016-2040 CVE-2016-2041

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here