Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 410965 (CVE-2012-1902) - <dev-db/phpmyadmin-3.5.2.2: Path Disclosure Vulnerability (CVE-2012-1902)
Summary: <dev-db/phpmyadmin-3.5.2.2: Path Disclosure Vulnerability (CVE-2012-1902)
Status: RESOLVED FIXED
Alias: CVE-2012-1902
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.phpmyadmin.net/home_page/s...
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 432340
Blocks:
  Show dependency tree
 
Reported: 2012-04-05 21:27 UTC by Tim Sammut (RETIRED)
Modified: 2012-10-02 06:27 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2012-04-05 21:27:33 UTC
From the upstream advisory at $URL:

Summary

Path disclosure due to missing verification of file presence.

Description

The show_config_errors.php scripts did not validate the presence of the configuration file, so an error message shows the full path of this file, leading to possible further attacks.

Severity

We consider this vulnerability to be non critical.

Mitigation factor

For the error messages to be displayed, php.ini's error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual).

Affected Versions

Versions 3.4.x are affected.

Solution

Upgrade to phpMyAdmin 3.4.10.2 or newer or apply the related patch listed below.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2012-04-10 21:35:58 UTC
CVE-2012-1902 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1902):
  show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a
  configuration file does not exist, allows remote attackers to obtain
  sensitive information via a direct request, which reveals the installation
  path in an error message about this missing file.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-09-27 19:09:12 UTC
GLSA vote: no.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2012-10-02 06:27:04 UTC
GLSA Vote: no too, closing noglsa.