Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 526416 (CVE-2014-8326) - dev-db/phpmyadmin: cross-site scripting (XSS) flaw fixed in versions 4.0.10.5, 4.1.14.6, and 4.2.10.1 (PMASA-2014-12) (CVE-2014-8326)
Summary: dev-db/phpmyadmin: cross-site scripting (XSS) flaw fixed in versions 4.0.10.5...
Status: RESOLVED FIXED
Alias: CVE-2014-8326
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 530054
Blocks:
  Show dependency tree
 
Reported: 2014-10-22 07:20 UTC by Agostino Sarubbo
Modified: 2015-08-22 17:41 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-10-22 07:20:13 UTC
From ${URL} :

The 4.0.10.5, 4.1.14.6, and 4.2.10.1 releases of phpMyAdmin fix a cross-site scripting (XSS) flaw in the SQL debug output:

""
With a crafted database or table name it is possible to trigger an XSS in SQL debug output when enabled and in server monitor page when viewing and analysing executed queries.
""

As noted in the upstream advisory, this issue can only be triggered by logged-in users.

References:

http://www.phpmyadmin.net/home_page/security/PMASA-2014-12.php



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-12-28 22:32:01 UTC
CVE-2014-8326 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8326):
  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x
  before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow
  remote authenticated users to inject arbitrary web script or HTML via a
  crafted (1) database name or (2) table name, related to the
  libraries/DatabaseInterface.class.php code for SQL debug output and the
  js/server_status_monitor.js code for the server monitor page.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-12-29 06:10:33 UTC
no GLSA for Cross Site Scripting

Setting cleanup dependency on bug 530054 to cleanup version: 4.1.14.3
Comment 3 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-03-14 15:37:42 UTC
15:33 < gentoovcs> jmbsvicetto → gentoo-x86 (dev-db/phpmyadmin/) Bump phpmyadmin to the latest releases and add 4.4.0_beta1. Address CVE-2014-{9218,9219} - fixes bug 531684. Address PMASA-2015-1 - fixes bug 542218. Drop old vulnerable versions.

Old version cleaned.
Comment 4 Sergey Popov gentoo-dev 2015-08-22 17:41:05 UTC
All necessary stuff is done. Thanks guys, closing as noglsa