*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: phpmyadmin

References:
DSA-1557-1 (http://www.debian.org/security/2008/dsa-1557)

Quoting:
"CVE-2008-1924

    Attackers with CREATE table permissions were allowed to read
    arbitrary files readable by the webserver via a crafted
    HTTP POST request.

CVE-2008-1567

    The PHP session data file stored the username and password of
    a logged in user, which in some setups can be read by a local
    user."

Note: CVE-2008-1149 has been treated in Bug #198745.

** Affects: phpmyadmin (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1567

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1924

-- 
[phpmyadmin] [CVE-2008-1567 CVE-2008-1924] insufficient input sanitising
https://bugs.launchpad.net/bugs/227283
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to