Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 215692

Summary: dev-db/phpmyadmin <2.11.5.1 Local session data disclosure (CVE-2008-1567)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: minor CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2
Whiteboard: B3 [ebuild]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-01 13:01:48 UTC
CVE-2008-1567 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1567):
  phpMyAdmin before 2.11.5.1 stores the (1) MySQL username, (2) password, and
  the (2) Blowfish secret key in plaintext in the /tmp Session file, which
  allows local users to obtain sensitive information.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-04-01 13:10:00 UTC

*** This bug has been marked as a duplicate of bug 215502 ***