[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ MDVSA-2014:126 ] phpmyadmin
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: [ MDVSA-2014:126 ] phpmyadmin
- From: security@xxxxxxxxxxxx
- Date: Tue, 08 Jul 2014 18:50:01 +0200
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2014:126
http://www.mandriva.com/en/support/security/
_______________________________________________________________________
Package : phpmyadmin
Date : July 8, 2014
Affected: Business Server 1.0
_______________________________________________________________________
Problem Description:
Multiple vulnerabilities has been discovered and corrected in
phpmyadmin:
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x
before 4.2.4 allow remote authenticated users to inject arbitrary web
script or HTML via a crafted (1) database name or (2) table name that
is improperly handled after presence in (a) the favorite list or (b)
recent tables (CVE-2014-4348).
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x
before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated
users to inject arbitrary web script or HTML via a crafted table
name that is improperly handled after a (1) hide or (2) unhide action
(CVE-2014-4349).
This upgrade provides the latest phpmyadmin version (4.2.5) to address
these vulnerabilities.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4348
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4349
http://sourceforge.net/p/phpmyadmin/news/
http://www.phpmyadmin.net/home_page/security/PMASA-2014-2.php
http://www.phpmyadmin.net/home_page/security/PMASA-2014-3.php
_______________________________________________________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
94dcec5bc68487ebb9e27567f290257d
mbs1/x86_64/phpmyadmin-4.2.5-1.mbs1.noarch.rpm
e4603acd4aaabb0127bdd9cb763d1bc5 mbs1/SRPMS/phpmyadmin-4.2.5-1.mbs1.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/support/security/advisories/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iD8DBQFTu/comqjQ0CJFipgRAkBsAKCH0tOH//7fgAqzbWgcP9SZeiql7wCdEiXC
3BWL3Jy4l4Ty9S/6mF9RjAU=
=BTEz
-----END PGP SIGNATURE-----
- Prev by Date:
CVE-2014-3074 - Runtime Linker Allows Privilege Escalation Via Arbitrary File Writes in IBM AIX
- Next by Date:
[security bulletin] HPSBMU03065 rev.1 - HP Operations Analytics, OpenSSL Vulnerability, SSL/TLS, Remote Code Execution, Denial of Service (DoS), Disclosure of Information
- Previous by thread:
CVE-2014-3074 - Runtime Linker Allows Privilege Escalation Via Arbitrary File Writes in IBM AIX
- Next by thread:
[security bulletin] HPSBMU03065 rev.1 - HP Operations Analytics, OpenSSL Vulnerability, SSL/TLS, Remote Code Execution, Denial of Service (DoS), Disclosure of Information
- Index(es):