Summary: | dev-db/phpmyadmin < 2.11.9.1: Remote code execution after successful auth (CVE-2008-4096) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Christian Hoffmann (RETIRED) <hoffie> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | borovoy.anton, mysql-bugs, rodrigo, veszig, wschlich |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
URL: | http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-7 | ||
Whiteboard: | B1? [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Christian Hoffmann (RETIRED)
![]() Maintainers, please bump. CVE-2008-4096 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4096): libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. Maintainers, please bump. We have a target delay of 5 days for B1 issues. phpmyadmin-2.11.9.1 is in the tree. Sorry for the delay. Arches, please test and mark stable: =dev-db/phpmyadmin-2.11.9.1 Target keywords : "alpha amd64 hppa ppc ppc64 sparc x86" ppc done ppc64 done alpha/sparc/x86 stable Stable for HPPA. amd64 stable All arches done, request filed. Removed phpmyadmin-2.11.8, -2.11.8.1. webapps done GLSA 200903-32 |