Debian DSA-2034-1 : phpmyadmin - several vulnerabilities

critical Nessus Plugin ID 45556

Language:

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2008-7251 phpMyAdmin may create a temporary directory, if the configured directory does not exist yet, with insecure filesystem permissions.

- CVE-2008-7252 phpMyAdmin uses predictable filenames for temporary files, which may lead to a local denial of service attack or privilege escalation.

- CVE-2009-4605 The setup.php script shipped with phpMyAdmin may unserialize untrusted data, allowing for cross site request forgery.

Solution

Upgrade the phpmyadmin package.

For the stable distribution (lenny), these problems have been fixed in version phpmyadmin 2.11.8.1-5+lenny4.

See Also

https://security-tracker.debian.org/tracker/CVE-2008-7251

https://security-tracker.debian.org/tracker/CVE-2008-7252

https://security-tracker.debian.org/tracker/CVE-2009-4605

https://www.debian.org/security/2010/dsa-2034

Plugin Details

Severity: Critical

ID: 45556

File Name: debian_DSA-2034.nasl

Version: 1.13

Type: local

Agent: unix

Published: 4/19/2010

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:phpmyadmin, cpe:/o:debian:debian_linux:5.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/17/2010

Exploitable With

Core Impact

Reference Information

CVE: CVE-2008-7251, CVE-2008-7252, CVE-2009-4605

BID: 37826

DSA: 2034