Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 440772 - dev-db/phpmyadmin : Obtaining current phpMyAdmin version from non SSL site is prone to MITM attack
Summary: dev-db/phpmyadmin : Obtaining current phpMyAdmin version from non SSL site is...
Status: RESOLVED DUPLICATE of bug 438804
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-01 16:12 UTC by Agostino Sarubbo
Modified: 2012-11-10 19:55 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-11-01 16:12:35 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=870012 :

Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5368 to the following 
vulnerability:

phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to 
phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site 
scripting (XSS) attacks by modifying this code.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5368
[2] http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php
[3] https://github.com/phpmyadmin/phpmyadmin/commit/50edafc0884aa15d0a1aa178089ac6a1ad2eb18a
[4] https://github.com/phpmyadmin/phpmyadmin/commit/a547f3d3e2cf36c6a904fa3e053fd8bddd3fbbb0
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-10 19:55:36 UTC

*** This bug has been marked as a duplicate of bug 438804 ***