Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 524366 (CVE-2014-7217) - dev-db/phpmyadmin: cross-site scripting (XSS) (CVE-2014-7217)
Summary: dev-db/phpmyadmin: cross-site scripting (XSS) (CVE-2014-7217)
Status: RESOLVED FIXED
Alias: CVE-2014-7217
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 530054
Blocks:
  Show dependency tree
 
Reported: 2014-10-03 10:05 UTC by Agostino Sarubbo
Modified: 2015-08-22 17:41 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-10-03 10:05:54 UTC
From ${URL} :

The 4.0.10.4, 4.1.14.5, and 4.2.9.1 releases of phpMyAdmin fix a cross-site scripting (XSS) flaw:

"With a crafted ENUM value it is possible to trigger an XSS in table search and table structure 
pages."

The attacker must have a valid login.

References:

http://www.phpmyadmin.net/home_page/security/PMASA-2014-11.php


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2014-10-03 14:47:57 UTC
This bump was already done[1], I was waiting to see if there was a request for a CVE in oss-security.

http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-db/phpmyadmin/

arches, please mark stable

=dev-db/phpmyadmin-4.0.10.4
=dev-db/phpmyadmin-4.1.14.5
=dev-db/phpmyadmin-4.2.9.1

Target Keywords : "alpha amd64 hppa ppc ppc64 sparc x86"
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2014-12-28 22:30:34 UTC
CVE-2014-7217 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-7217):
  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x
  before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow
  remote authenticated users to inject arbitrary web script or HTML via a
  crafted ENUM value that is improperly handled during rendering of the (1)
  table search or (2) table structure page, related to
  libraries/TableSearch.class.php and libraries/Util.class.php.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2014-12-29 06:08:12 UTC
no GLSA for Cross Site Scripting

Setting cleanup dependency on bug 530054 to cleanup version: 4.1.14.3
Comment 4 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-03-14 15:37:16 UTC
15:33 < gentoovcs> jmbsvicetto → gentoo-x86 (dev-db/phpmyadmin/) Bump phpmyadmin to the latest releases and add 4.4.0_beta1. Address CVE-2014-{9218,9219} - fixes bug 531684. Address PMASA-2015-1 - fixes bug 542218. Drop old vulnerable versions.

Old version cleaned.
Comment 5 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-08-22 17:41:13 UTC
Closed