Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 250451 - dev-db/phppgadmin: <=4.2.1 "_language" Local File Inclusion Vulnerability (CVE-2008-5587)
Summary: dev-db/phppgadmin: <=4.2.1 "_language" Local File Inclusion Vulnerability (CV...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/33014/
Whiteboard: C4 [noglsa]
Keywords:
: 252762 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-12-09 22:34 UTC by Matti Bickel (RETIRED)
Modified: 2009-01-03 21:08 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matti Bickel (RETIRED) gentoo-dev 2008-12-09 22:34:21 UTC
From secunia: (http://secunia.com/advisories/33014/)


DESCRIPTION:Dun has discovered a vulnerability in phpPgAdmin, which can be
exploited by malicious people to disclose sensitive information.

Input passed via the "_language" parameter to libraries/lib.inc.php
is not properly sanitised before being used to include files. This
can be exploited to include arbitrary files from local resources via
directory traversal attacks and URL-encoded NULL bytes.

Successful exploitation of this vulnerability requires that
"register_globals" is enabled.

This vulnerability is confirmed in version 4.2.1. Other versions may
also be affected.

SOLUTION:
Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY:
dun

ORIGINAL ADVISORY:
http://milw0rm.com/exploits/7363

In the default configuration "register_globals" is set to off on gentoo systems, so only specific configurations are affected.
Comment 1 Matti Bickel (RETIRED) gentoo-dev 2008-12-09 22:37:03 UTC
Very low impact, so rating C4.
Comment 2 stupendoussteve 2008-12-17 03:42:30 UTC
This is now assigned CVE-2008-5587
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-12-17 16:12:19 UTC
CVE-2008-5587 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5587):
  Directory traversal vulnerability in libraries/lib.inc.php in
  phpPgAdmin 4.2.1 and earlier, when register_globals is enabled,
  allows remote attackers to read arbitrary files via a .. (dot dot) in
  the _language parameter to index.php.

Comment 4 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2008-12-28 01:38:14 UTC
*** Bug 252762 has been marked as a duplicate of this bug. ***
Comment 5 Gunnar Wrobel (RETIRED) gentoo-dev 2008-12-28 21:27:07 UTC
Removed dev-db/phppgadmin-4.2.1, added 4.2.2.

Targets:

  amd64 hppa ppc sparc x86
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2008-12-29 18:22:58 UTC
ppc stable
Comment 7 Friedrich Oslage (RETIRED) gentoo-dev 2008-12-30 22:48:15 UTC
sparc stable
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2008-12-31 16:19:33 UTC
x86 stable
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2009-01-02 18:38:22 UTC
Stable for HPPA.
Comment 10 Markus Meier gentoo-dev 2009-01-03 21:00:29 UTC
amd64 stable, all arches done.
Comment 11 Tobias Heinlein (RETIRED) gentoo-dev 2009-01-03 21:08:31 UTC
Thanks everyone. C4 -> noglsa