Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 83190
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Aarni Honka <aarni.honka@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 83190 depends on: 83792 Show dependency tree
Bug 83190 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-02-24 07:22 0000
TITLE:
phpMyAdmin Local File Inclusion and Cross-Site Scripting

SECUNIA ADVISORY ID:
SA14382

VERIFY ADVISORY:
http://secunia.com/advisories/14382/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting, Exposure of sensitive information

WHERE:
>From remote

SOFTWARE:
phpMyAdmin 2.x
http://secunia.com/product/1720/
phpMyAdmin 1.x
http://secunia.com/product/1719/

DESCRIPTION:
Maksymilian Arciemowicz has reported some vulnerabilities in
phpMyAdmin, which can be exploited by malicious people to conduct
cross-site scripting attacks and disclose sensitive information.

1) Input passed to the "strServer", "cfg[BgcolorOne]", and
"strServerChoice" parameters in "select_server.lib.php", the
"bgcolor" and "row_no" parameters in "display_tbl_links.lib.php", the
"left_font_family" parameter in "theme_left.css.php", and the
"right_font_family" parameter in "theme_right.css.php" is not
properly sanitised before being returned to users. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.

Successful exploitation requires that "register_globals" is enabled.

2) Input passed to the "GLOBALS[cfg][ThemePath]" parameter in
"phpmyadmin.css.php" and "cfg[Server][extension]" parameter in
"database_interface.lib.php" is not properly verified before being
used to include files. This can be exploited to include arbitrary
files from local resources.

Successful exploitation requires that "register_globals" is enabled
and that "magic_quotes_gpc" is disabled.

The vulnerabilities have been reported in version 2.6.1. Other
versions may also be affected.

It is also possible to disclose the full path to certain scripts by
accessing them directly.

SOLUTION:
Update to version 2.6.1-pl1.
http://sourceforge.net/project/showfiles.php?group_id=23067

PROVIDED AND/OR DISCOVERED BY:
Maksymilian Arciemowicz

ORIGINAL ADVISORY:
http://sourceforge.net/tracker/index.php?func=detail&aid=1149383&group_id=23067&atid=377408
http://sourceforge.net/tracker/index.php?func=detail&aid=1149381&group_id=23067&atid=377408

------- Comment #1 From Luke Macken (RETIRED) 2005-02-24 08:40:54 0000 -------
twp, please bump.

------- Comment #2 From Andreas Korthaus 2005-02-24 18:00:35 0000 -------
"phpMyAdmin 2.6.1-pl2 is released

We are sorry to report that the release of 2.6.1-pl1 introduced an instability, producing various problems. This has been fixed, and here is 2.6.1-pl2." 

http://www.phpmyadmin.net/home_page/

------- Comment #3 From Martin Holzer (RETIRED) 2005-02-27 02:59:24 0000 -------
2.6.1-pl2 is in cvs now

------- Comment #4 From Matthias Geerdsen 2005-02-27 06:51:40 0000 -------
arches, pls test and mark phpmyadmin-2.6.1_p2 stable

current KEYWORDS="~alpha ~ppc ~hppa ~sparc ~x86 ~amd64 ~mips"
target KEYWORDS="alpha ppc hppa sparc x86 amd64 ~mips"

_____

http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-1
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-2

------- Comment #5 From Jason Wever (RETIRED) 2005-02-27 09:34:35 0000 -------
Stable on sparc.

------- Comment #6 From Olivier Crete 2005-02-28 13:06:26 0000 -------
x86 stable

------- Comment #7 From Michael Hanselmann (hansmi) (RETIRED) 2005-02-28 13:32:05 0000 -------
Stable on ppc.

------- Comment #8 From Simon Stelling (RETIRED) 2005-02-28 13:56:53 0000 -------
amd64 done

------- Comment #9 From Thierry Carrez (RETIRED) 2005-03-01 03:09:56 0000 -------
*** Bug 83590 has been marked as a duplicate of this bug. ***

------- Comment #10 From Bryan Østergaard (RETIRED) 2005-03-01 10:24:30 0000 -------
Stable on alpha.

------- Comment #11 From Thierry Carrez (RETIRED) 2005-03-01 10:31:20 0000 -------
GLSA vote please

------- Comment #12 From Sune Kloppenborg Jeppesen 2005-03-01 11:52:49 0000 -------
I vote YES. We already released a GLSA 200411-36 for a similar issue.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-03-02 01:32:42 0000 -------
OK I agree, GLSA there will be

------- Comment #14 From Thierry Carrez (RETIRED) 2005-03-02 13:37:19 0000 -------
Apparently this allows remote PHP file inclusion on some setups.

------- Comment #15 From Sune Kloppenborg Jeppesen 2005-03-03 14:26:47 0000 -------
GLSA 200503-07

------- Comment #16 From René Nussbaumer 2005-06-26 05:59:25 0000 -------
ebuild no longer in portage.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug