Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 564238 - <dev-db/phpmyadmin-{4.4.15.2,4.5.3.1}: Content spoofing vulnerability when redirecting user to an external site
Summary: <dev-db/phpmyadmin-{4.4.15.2,4.5.3.1}: Content spoofing vulnerability when re...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://www.phpmyadmin.net/security/P...
Whiteboard: B4 [noglsa]
Keywords:
Depends on: CVE-2015-8669
Blocks:
  Show dependency tree
 
Reported: 2015-10-27 08:27 UTC by Agostino Sarubbo
Modified: 2016-02-25 07:49 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-10-27 08:27:43 UTC
From ${URL} :

PMASA-2015-5

Announcement-ID: PMASA-2015-5

Date: 2015-10-23

Summary

Content spoofing vulnerability when redirecting user to an external site

Description

This vulnerability allows an attacker to perform a content spoofing attack using the phpMyAdmin's redirection mechanism to external sites.

Severity

We consider this vulnerability to be non critical since the spoofed content is escaped and no HTML injection is possible.

Affected Versions

Versions 4.4.x (prior to 4.4.15.1) and 4.5.x (prior to 4.5.1) are affected.

Solution

Upgrade to phpMyAdmin 4.4.15.1 or newer, or 4.5.1 or newer or apply patch listed below.

References

Thanks to Lalith Rallabhandi for reporting this vulnerability.

Assigned CVE ids: 2015-7873

CWE ids: CWE-661 CWE-20

Patches

The following commits have been made on the 4.4 branch to fix this issue:

2b31866fe0b30b867aaf5b5fedb11adb354e037f
The following commits have been made on the 4.5 branch to fix this issue:

cd097656758f981f80fb9029c7d6b4294582b706



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2015-11-04 22:14:23 UTC
22:12 < gentoovcs> jmbsvicetto → repo/gentoo (dev-db/phpmyadmin/) [dev-db/phpmyadmin] Version bump to address PMASA-2015-5 - fixes bug 564238. Drop vulnerable version.
22:12 < willikins> gentoovcs: https://bugs.gentoo.org/564238 "dev-db/phpmyadmin: Content spoofing vulnerability when redirecting user to an external site"; Gentoo Security, Vulnerabilities; IN_P; ago:security

Package bumped.
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2016-02-25 07:49:00 UTC
Thank you all for you work. 
Closing as [noglsa].