Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 479870 (CVE-2013-5029) - <dev-db/phpmyadmin-4.0.5: Clickjacking Vulnerability (CVE-2013-5029)
Summary: <dev-db/phpmyadmin-4.0.5: Clickjacking Vulnerability (CVE-2013-5029)
Status: RESOLVED FIXED
Alias: CVE-2013-5029
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/54381/
Whiteboard: B4 [glsa]
Keywords:
: 468516 (view as bug list)
Depends on:
Blocks: CVE-2013-3238 CVE-2013-4995
  Show dependency tree
 
Reported: 2013-08-05 20:31 UTC by Agostino Sarubbo
Modified: 2013-11-04 11:57 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-08-05 20:31:40 UTC
From ${URL} :

Description

A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to 
conduct clickjacking attacks.

The application allows users to perform certain actions via HTTP requests without performing any 
validity checks to verify the requests. This can be exploited to perform certain unspecified 
actions by tricking a user into clicking a specially crafted link via clickjacking.

The vulnerability is reported in versions 3.5.x.


Solution:
Upgrade to version 4.0.5 or later.

Provided and/or discovered by:
The vendor credits Emanuel Bronshtein.

Original Advisory:
PMASA-2013-10:
http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php




@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Chris Reffett gentoo-dev Security 2013-08-05 21:43:11 UTC
Looks like it's the end of the line for 3.5.x, according to the link.
Comment 2 Alex Legler (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2013-08-17 23:56:56 UTC
*** Bug 468516 has been marked as a duplicate of this bug. ***
Comment 3 Alex Legler (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2013-08-18 00:01:16 UTC
Arches, please test and mark stable:
=dev-db/phpmyadmin-4.0.5
Target keywords : "alpha amd64 hppa ppc ppc64 sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2013-08-18 12:24:00 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-08-18 12:49:30 UTC
alpha stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-08-18 12:49:47 UTC
sparc stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-08-18 12:50:06 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-08-19 13:59:17 UTC
ppc stable
Comment 9 Jeroen Roovers gentoo-dev 2013-08-20 14:15:38 UTC
Stable for HPPA.
Comment 10 Agostino Sarubbo gentoo-dev 2013-08-24 12:35:32 UTC
ppc64 stable
Comment 11 Sergey Popov gentoo-dev 2013-08-24 19:39:53 UTC
Thanks for your work

GLSA vote: no
Comment 12 Alex Legler (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2013-08-24 20:08:46 UTC
GLSA with 465420, 467808, 478696
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2013-08-24 20:15:46 UTC
CVE-2013-5029 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5029):
  phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass
  the clickjacking protection mechanism via certain vectors related to
  Header.class.php.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2013-11-04 11:57:13 UTC
This issue was resolved and addressed in
 GLSA 201311-02 at http://security.gentoo.org/glsa/glsa-201311-02.xml
by GLSA coordinator Sergey Popov (pinkbyte).