Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE: 2020:0405-1 Moderate: phpMyAdmin SQL Injection Issues Fixed

opensuse
Calendar Grey March 29, 2020
Dist Opensuse Esm H88
openSUSE Security Patch for phpMyAdmin resolves several SQL injection vulnerabilities identified in version 4.9.5.
An update that fixes three vulnerabilities is now available.

Description

This update for phpMyAdmin to version 4.9.5 fixes the following issues:

- phpmyadmin was updated to 4.9.5:

- CVE-2020-10804: Fixed an SQL injection in the user accounts page,

particularly when changing a password (boo#1167335 PMASA-2020-2).

- CVE-2020-10802: Fixed an SQL injection in the search feature

(boo#1167336 PMASA-2020-3).

- CVE-2020-10803: Fixed an SQL injection and XSS when displaying results

(boo#1167337 PMASA-2020-4).

- Removed the "options" field for the external transformation.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2020-405=1

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):

phpMyAdmin-4.9.5-43.1

References

https://www.suse.com/security/cve/CVE-2020-10802.html

https://www.suse.com/security/cve/CVE-2020-10803.html

https://www.suse.com/security/cve/CVE-2020-10804.html

https://bugzilla.suse.com/1167335

https://bugzilla.suse.com/1167336

https://bugzilla.suse.com/1167337

--

Announcement ID: openSUSE-SU-2020:0405-1
Rating: moderate
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here