From the upstream advisory at $URL: Summary Path disclosure due to missing verification of file presence. Description The show_config_errors.php scripts did not validate the presence of the configuration file, so an error message shows the full path of this file, leading to possible further attacks. Severity We consider this vulnerability to be non critical. Mitigation factor For the error messages to be displayed, php.ini's error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual). Affected Versions Versions 3.4.x are affected. Solution Upgrade to phpMyAdmin 3.4.10.2 or newer or apply the related patch listed below.
CVE-2012-1902 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1902): show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
GLSA vote: no.
GLSA Vote: no too, closing noglsa.