Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian 4.0 DSA-1641-1 Critical: PhpMyAdmin Remote Threats Addressed

debian
Calendar Grey September 20, 2008
Debian Logo
Security flaws in phpMyAdmin identified in Debian Security Advisory DSA-1641-1. It is advised to update for enhanced security.
Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administrate MySQL databases over the web

Summary


Remote authenticated users could execute arbitrary code on the
host running phpMyAdmin through manipulation of a script parameter.

CVE-2008-3457

Cross site scripting through the setup script was possible in
rare circumstances.

CVE-2008-3456

Protection has been added against remote websites loading phpMyAdmin
into a frameset.

CVE-2008-3197

Cross site request forgery allowed remote attackers to create a new
database, but not perform any other action on it.

For the stable distribution (etch), these problems have been fixed in
version 4:2.9.1.1-8.

For the unstable distribution (sid), these problems have been fixed in
version 4:2.11.8.1-2.

We recommend that you upgrade your phpmyadmin package.

Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here