Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 479870 (CVE-2013-5029)

Summary: <dev-db/phpmyadmin-4.0.5: Clickjacking Vulnerability (CVE-2013-5029)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: a3li, admwiggin, kripton, toto, web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://secunia.com/advisories/54381/
See Also: https://bugs.gentoo.org/show_bug.cgi?id=478696
Whiteboard: B4 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 467080, 478696    

Description Agostino Sarubbo gentoo-dev 2013-08-05 20:31:40 UTC
From ${URL} :

Description

A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to 
conduct clickjacking attacks.

The application allows users to perform certain actions via HTTP requests without performing any 
validity checks to verify the requests. This can be exploited to perform certain unspecified 
actions by tricking a user into clicking a specially crafted link via clickjacking.

The vulnerability is reported in versions 3.5.x.


Solution:
Upgrade to version 4.0.5 or later.

Provided and/or discovered by:
The vendor credits Emanuel Bronshtein.

Original Advisory:
PMASA-2013-10:
http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php




@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-05 21:43:11 UTC
Looks like it's the end of the line for 3.5.x, according to the link.
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-08-17 23:56:56 UTC
*** Bug 468516 has been marked as a duplicate of this bug. ***
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-08-18 00:01:16 UTC
Arches, please test and mark stable:
=dev-db/phpmyadmin-4.0.5
Target keywords : "alpha amd64 hppa ppc ppc64 sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2013-08-18 12:24:00 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-08-18 12:49:30 UTC
alpha stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-08-18 12:49:47 UTC
sparc stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-08-18 12:50:06 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-08-19 13:59:17 UTC
ppc stable
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2013-08-20 14:15:38 UTC
Stable for HPPA.
Comment 10 Agostino Sarubbo gentoo-dev 2013-08-24 12:35:32 UTC
ppc64 stable
Comment 11 Sergey Popov gentoo-dev 2013-08-24 19:39:53 UTC
Thanks for your work

GLSA vote: no
Comment 12 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-08-24 20:08:46 UTC
GLSA with 465420, 467808, 478696
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2013-08-24 20:15:46 UTC
CVE-2013-5029 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5029):
  phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass
  the clickjacking protection mechanism via certain vectors related to
  Header.class.php.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2013-11-04 11:57:13 UTC
This issue was resolved and addressed in
 GLSA 201311-02 at http://security.gentoo.org/glsa/glsa-201311-02.xml
by GLSA coordinator Sergey Popov (pinkbyte).