*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: phpmyadmin

References:
PMASA-2008-1 
(http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1)

Quoting:
"Description:
We received an advisory from Richard Cunningham, and we wish to thank him for 
his work. phpMyAdmin used the $_REQUEST superglobal as a source for its 
parameters, instead of $_GET and $_POST. This means that on most servers, a 
cookie with the same name as one of phpMyAdmin's parameters can interfere.
Another application could set a cookie for the root path "/" with a "sql_query" 
name, therefore overriding the user-submitted sql_query because by default, the 
$_REQUEST superglobal imports first GET, then POST then COOKIE data.

Severity:
We consider this vulnerability to be serious.

Mitigation factor:
An attacker must trick the victim into visiting a page on the same web server 
where he has placed code that creates a malicious cookie.

Affected versions:
Versions before 2.11.5.

Solution:
Upgrade to phpMyAdmin 2.11.5 or newer, where $_REQUEST is rebuilt to not 
contain cookies."

** Affects: phpmyadmin (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

-- 
[phpmyadmin] [PMASA-2008-1] SQL injection vulnerability (Delayed Cross Site 
Request Forgery)
https://bugs.launchpad.net/bugs/198745
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to