2019-11-24
ALT-BU-2019-4084-1
Branch sisyphus update bulletin.
Package phpMyAdmin updated to version 4.9.2-alt1 for branch sisyphus in task 241526.
Closed vulnerabilities
Published: 2019-05-18
BDU:2019-04000
Уязвимость веб-приложения для администрирования систем управления базами данных phpMyAdmin, связанная с подделкой межсайтовых запросов, позволяющая нарушителю удалить любой сервер на странице установки
Severity: MEDIUM (4.3)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References:
Published: 2019-09-13
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
References:
- openSUSE-SU-2019:2211
- openSUSE-SU-2019:2211
- openSUSE-SU-2020:0056
- openSUSE-SU-2020:0056
- http://packetstormsecurity.com/files/154483/phpMyAdmin-4.9.0.1-Cross-Site-Request-Forgery.html
- http://packetstormsecurity.com/files/154483/phpMyAdmin-4.9.0.1-Cross-Site-Request-Forgery.html
- http://seclists.org/fulldisclosure/2019/Sep/23
- http://seclists.org/fulldisclosure/2019/Sep/23
- https://github.com/phpmyadmin/phpmyadmin/commit/427fbed55d3154d96ecfc1c7784d49eaa3c04161
- https://github.com/phpmyadmin/phpmyadmin/commit/427fbed55d3154d96ecfc1c7784d49eaa3c04161
- https://github.com/phpmyadmin/phpmyadmin/commit/7d21d4223bdbe0306593309132b4263d7087d13b
- https://github.com/phpmyadmin/phpmyadmin/commit/7d21d4223bdbe0306593309132b4263d7087d13b
- FEDORA-2019-644b438f51
- FEDORA-2019-644b438f51
- FEDORA-2019-6404181bf9
- FEDORA-2019-6404181bf9
- FEDORA-2019-3b5a7abe17
- FEDORA-2019-3b5a7abe17
- Exploit Database
- Exploit Database
Published: 2019-11-23
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-18622
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- openSUSE-SU-2019:2599
- openSUSE-SU-2019:2599
- openSUSE-SU-2020:0056
- openSUSE-SU-2020:0056
- FEDORA-2019-8f55b515f1
- FEDORA-2019-8f55b515f1
- FEDORA-2019-db68ae1fca
- FEDORA-2019-db68ae1fca
- GLSA-202003-39
- GLSA-202003-39
- https://www.phpmyadmin.net/security/PMASA-2019-5/
- https://www.phpmyadmin.net/security/PMASA-2019-5/
Published: 2019-12-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-19617
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/phpmyadmin/phpmyadmin/commit/1119de642b136d20e810bb20f545069a01dd7cc9
- https://github.com/phpmyadmin/phpmyadmin/commit/1119de642b136d20e810bb20f545069a01dd7cc9
- https://github.com/phpmyadmin/phpmyadmin/compare/RELEASE_4_9_1...RELEASE_4_9_2
- https://github.com/phpmyadmin/phpmyadmin/compare/RELEASE_4_9_1...RELEASE_4_9_2
- [debian-lts-announce] 20191208 [SECURITY] [DLA 2024-1] phpmyadmin security update
- [debian-lts-announce] 20191208 [SECURITY] [DLA 2024-1] phpmyadmin security update
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- [debian-lts-announce] 20201025 [SECURITY] [DLA 2413-1] phpmyadmin security update
- https://www.phpmyadmin.net/news/2019/11/22/phpmyadmin-492-released/
- https://www.phpmyadmin.net/news/2019/11/22/phpmyadmin-492-released/