Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 242834 - dev-db/phpmyadmin < 2.11.9.2: Bypass XSS Protection via NUL Byte when using MSIE
Summary: dev-db/phpmyadmin < 2.11.9.2: Bypass XSS Protection via NUL Byte when using MSIE
Status: RESOLVED DUPLICATE of bug 238592
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-19 23:21 UTC by Matti Bickel (RETIRED)
Modified: 2008-10-20 08:02 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matti Bickel (RETIRED) gentoo-dev 2008-10-19 23:21:34 UTC
From $URL:

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence. 

CVE is currently under review.

Suggested fix is to upgrade to 2.11.9.2

Issue is public, so leaving open.
Comment 1 Matti Bickel (RETIRED) gentoo-dev 2008-10-19 23:35:56 UTC
already fixed in tree, sorry for the spam... i will check that next time
Comment 2 Christian Hoffmann (RETIRED) gentoo-dev 2008-10-20 08:01:58 UTC
The fact that the necessary package is in the tree does not remove the need for tracking bug, but in this case we handled it already, so, marking as DUPE.
Comment 3 Christian Hoffmann (RETIRED) gentoo-dev 2008-10-20 08:02:18 UTC

*** This bug has been marked as a duplicate of bug 238592 ***