Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE-Request -- phpMyAdmin -- PMASA-2011-11 and PMASA-2011-12
From: Josh Bressers <bressers () redhat com>
Date: Tue, 26 Jul 2011 15:43:22 -0400 (EDT)

----- Original Message -----
Hello Josh, Steve, vendors,

the following two doesn't seem to have CVE identifiers yet:
1) http://www.phpmyadmin.net/home_page/security/PMASA-2011-11.php

A local file inclusion and arbitrary SQL code execution flaws were
found in the way phpMyAdmin, the MySQL over WWW administration tool,
performed 'export_type' sanitization, when retrieving and verifying
relation schema export options. A local attacker could use this flaw
obtain security sensitive information or, potentially, execute
arbitrary SQL code with the privileges of the user running the query.

[1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-11.php
[2] http://www.phpmyadmin.net/home_page/news.php
[3] https://bugzilla.redhat.com/show_bug.cgi?id=725383

Upstream patches:

Further flaw exploitation note:
An attacker must be logged in via phpMyAdmin to exploit this problem.

Affected versions:
Versions 3.4.0 to are affected.

2) http://www.phpmyadmin.net/home_page/security/PMASA-2011-12.php

A session values manipulation flaw was found in the way phpMyAdmin,
MySQL over WWW administration tool, performed sanitization of the
user-provided query string, when the Swekey extension based
authentication method was enabled. A remote attacker could use this
to manipulate the PHP session superglobal variable via
query string provided to the Swekey authentication module.

[1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-12.php
[2] http://www.phpmyadmin.net/home_page/news.php
[3] http://seclists.org/fulldisclosure/2011/Jul/300
[4] https://bugzilla.redhat.com/show_bug.cgi?id=725384

Upstream patches:

Patches against v3.3 branch:

Affected Versions:
The and earlier versions are affected.
Branch 2.11.x is not affected by this.

3) The other two recent phpMyAdmin issues (addressed in v3.3.10.3,
v3.4.3.2) already have CVE identifiers:
[1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php
[2] http://www.phpmyadmin.net/home_page/security/PMASA-2011-9.php

Cc-ed phpMyAdmin upstream contact, Herman van Rink, to correct me on
the description of the 1) and 2) flaws, where appropriate.

Josh, Steve, could you please allocate CVE ids for 1)

Use CVE-2011-2718 for PMASA-2011-11

and 2) PMASA-2011-12.php issues?

Use CVE-2011-2719 for PMASA-2011-12



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]