Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 266438 (CVE-2009-1285) - <dev-db/phpmyadmin-3.2.0: Execution of arbitrary PHP code (CVE-2009-1285)
Summary: <dev-db/phpmyadmin-3.2.0: Execution of arbitrary PHP code (CVE-2009-1285)
Status: RESOLVED FIXED
Alias: CVE-2009-1285
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.phpmyadmin.net/home_page/s...
Whiteboard: ~1 [noglsa]
Keywords:
: 274804 (view as bug list)
Depends on:
Blocks:
 
Reported: 2009-04-16 21:44 UTC by Alex Legler (RETIRED)
Modified: 2009-06-23 23:06 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-04-16 21:44:28 UTC
CVE-2009-1285 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1285):
  Static code injection vulnerability in the getConfigFile function in
  setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2
  allows remote attackers to inject arbitrary PHP code into
  configuration files.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-06-19 14:39:44 UTC
+*phpmyadmin-3.2.0 (19 Jun 2009)
+*phpmyadmin-2.11.9.5 (19 Jun 2009)
+
+  19 Jun 2009; Alex Legler <a3li@gentoo.org> +phpmyadmin-2.11.9.5.ebuild,
+  -phpmyadmin-3.1.2.ebuild, +phpmyadmin-3.2.0.ebuild:
+  Non-maintainer commit: Version bump, security bugs 263711 and 266438, bump
+  request 270877.
+
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-23 20:42:48 UTC
*** Bug 274804 has been marked as a duplicate of this bug. ***
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-23 23:06:13 UTC
*** Bug 274804 has been marked as a duplicate of this bug. ***