ALT-PU-2016-1527-1
Package phpMyAdmin updated to version 4.6.1-alt1 for branch sisyphus in task 164952.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-2206
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
- FEDORA-2015-3287
- FEDORA-2015-3287
- FEDORA-2015-3329
- FEDORA-2015-3329
- FEDORA-2015-3336
- FEDORA-2015-3336
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- DSA-3382
- DSA-3382
- MDVSA-2015:186
- MDVSA-2015:186
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-1.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-1.php
- 72949
- 72949
- 1031871
- 1031871
- https://github.com/phpmyadmin/phpmyadmin/commit/b2f1e895038a5700bf8e81fb9a5da36cbdea0eeb
- https://github.com/phpmyadmin/phpmyadmin/commit/b2f1e895038a5700bf8e81fb9a5da36cbdea0eeb
Modified: 2024-11-21
CVE-2015-3902
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- DSA-3382
- DSA-3382
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-2.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-2.php
- 74657
- 74657
- 1032404
- 1032404
- https://github.com/phpmyadmin/phpmyadmin/commit/ee92eb9bab8e2d546756c1d4aec81ec7c8e44b83
- https://github.com/phpmyadmin/phpmyadmin/commit/ee92eb9bab8e2d546756c1d4aec81ec7c8e44b83
Modified: 2024-11-21
CVE-2015-3903
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- http://cxsecurity.com/issue/WLB-2015050095
- http://cxsecurity.com/issue/WLB-2015050095
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- http://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.html
- http://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.html
- DSA-3382
- DSA-3382
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.php
- 20150514 phpMyAdmin 4.4.6 Man-In-the-Middle API Github
- 20150514 phpMyAdmin 4.4.6 Man-In-the-Middle API Github
- 74660
- 74660
- 1032403
- 1032403
- https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4
- https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4