Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 354227 (CVE-2011-0986) - <dev-db/phpmyadmin-3.4.0: multiple vulnerabilities (CVE-2011-{0986,0987})
Summary: <dev-db/phpmyadmin-3.4.0: multiple vulnerabilities (CVE-2011-{0986,0987})
Status: RESOLVED FIXED
Alias: CVE-2011-0986
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.phpmyadmin.net/home_page/n...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks: CVE-2010-4480
  Show dependency tree
 
Reported: 2011-02-09 12:33 UTC by Marcin Mirosław
Modified: 2012-01-04 23:42 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcin Mirosław 2011-02-09 12:33:51 UTC
"Welcome to these two security releases."
This is security fix, please bump without huge delay;)

Reproducible: Always
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-02-10 07:06:31 UTC
This appears to be due to http://www.phpmyadmin.net/home_page/security/PMASA-2011-1.php.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2011-02-15 12:40:24 UTC
There is another security release this one a little bit more serious:
http://www.phpmyadmin.net/home_page/security/PMASA-2011-2.php

Announcement-ID: PMASA-2011-2

SQL query could be executed under another user.
Description

It was possible to create a bookmark which would be executed unintentionally by other users.
Severity

We consider this vulnerability to be critical.
Mitigation factor

To use this vulnerability, phpMyAdmin configuration storage needs to be set up and enabled and bookmarks function needs to be enabled.
Affected Versions

The 2.11.x and 3.3.x versions are affected.
Solution

Upgrade to phpMyAdmin 3.3.9.2 or newer (2.11.11.3 or newer for the older family) or apply the related patch listed below.
References

This issue was found by Michal Čihař.

Assigned CVE ids: CVE-2011-0987

CWE ids: CWE-661 CWE-89

I would recommend to skip 3.3.9.1 and go direct to 3.3.9.2
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-05-17 16:14:35 UTC
Arches, please test and mark stable:
=dev-db/phpmyadmin-3.4.0
Target keywords : "alpha amd64 hppa ppc ppc64 sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2011-05-18 16:46:06 UTC
amd64 ok
Comment 5 Markos Chandras (RETIRED) gentoo-dev 2011-05-19 08:59:26 UTC
Works perfect on my VPS. amd64 done. Thanks Agostino
Comment 6 Thomas Kahle (RETIRED) gentoo-dev 2011-05-19 09:02:26 UTC
x86 stable. Thanks
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2011-05-21 05:57:05 UTC
Stable for HPPA.
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2011-05-21 17:23:41 UTC
alpha/sparc stable
Comment 9 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-05-22 18:08:48 UTC
ppc/ppc64 stable, last arch done
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2011-05-23 02:33:32 UTC
Thanks, everyone. GLSA request filed.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2011-06-13 18:07:57 UTC
CVE-2011-0987 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0987):
  The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin
  2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly
  restrict bookmark queries, which makes it easier for remote authenticated
  users to trigger another user's execution of a SQL query by creating a
  bookmark.

CVE-2011-0986 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0986):
  phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not
  properly handle the absence of the (1) README, (2) ChangeLog, and (3)
  LICENSE files, which allows remote attackers to obtain the installation path
  via a direct request for a nonexistent file.
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2012-01-04 23:42:01 UTC
This issue was resolved and addressed in
 GLSA 201201-01 at http://security.gentoo.org/glsa/glsa-201201-01.xml
by GLSA coordinator Tim Sammut (underling).