Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 522844 (CVE-2014-6300) - dev-db/phpmyadmin: XSS flaw possibly leading to root account creation (PMASA-2014-10) (CVE-2014-6300)
Summary: dev-db/phpmyadmin: XSS flaw possibly leading to root account creation (PMASA-...
Status: RESOLVED FIXED
Alias: CVE-2014-6300
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [glsa]
Keywords:
Depends on: 530054
Blocks:
  Show dependency tree
 
Reported: 2014-09-15 08:11 UTC by Agostino Sarubbo
Modified: 2015-05-31 19:21 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-09-15 08:11:15 UTC
From ${URL} :

The upstream phpMyAdmin PMASA-2014-10 advisory fixes the following issue:

""
By deceiving a logged-in user to click on a crafted URL, it is possible to perform remote code execution and in some cases, create a root account due to a DOM based XSS vulnerability in the micro history feature.

...

Versions 4.0.x (prior to 4.0.10.3), 4.1.x (prior to 4.1.14.4) and 4.2.x (prior to 4.2.8.1) are affected.
""


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-12-28 22:31:09 UTC
CVE-2014-6300 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6300):
  Cross-site scripting (XSS) vulnerability in the micro history implementation
  in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before
  4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and
  consequently conduct a cross-site request forgery (CSRF) attack to create a
  root account, via a crafted URL, related to js/ajax.js.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-12-29 06:05:34 UTC
no GLSA for Cross Site Scripting

Setting cleanup dependency on bug 530054 to cleanup version: 4.1.14.3
Comment 3 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-03-14 15:36:56 UTC
15:33 < gentoovcs> jmbsvicetto → gentoo-x86 (dev-db/phpmyadmin/) Bump phpmyadmin to the latest releases and add 4.4.0_beta1. Address CVE-2014-{9218,9219} - fixes bug 531684. Address PMASA-2015-1 - fixes bug 542218. Drop old vulnerable versions.

Old version cleaned.
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-03-14 15:39:32 UTC
(In reply to Jorge Manuel B. S. Vicetto from comment #3)
> 15:33 < gentoovcs> jmbsvicetto → gentoo-x86 (dev-db/phpmyadmin/) Bump
> phpmyadmin to the latest releases and add 4.4.0_beta1. Address
> CVE-2014-{9218,9219} - fixes bug 531684. Address PMASA-2015-1 - fixes bug
> 542218. Drop old vulnerable versions.
> 
> Old version cleaned.

Thanks
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-03-14 15:45:58 UTC
Re-opening for GLSA together with bug 530054
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2015-05-31 19:21:26 UTC
This issue was resolved and addressed in
 GLSA 201505-03 at https://security.gentoo.org/glsa/201505-03
by GLSA coordinator Kristian Fiskerstrand (K_F).