Fedora 16 : phpMyAdmin-3.5.0-1.fc16 (2012-5624)

medium Nessus Plugin ID 58925

Synopsis

The remote Fedora host is missing a security update.

Description

Changes for 3.5.0.0 (2012-04-07) :

- [interface] Add support for mass prefix change.

- [display] 'up to date' message on main page when current version is up to date

- [feature] Update to jQuery 1.6.2

- [search] Show/hide db search results

- [patch] Add gettext wrappers around a message

- [cleanup] Remove deprecated function PMA_DBI_get_fields

- [feature] Remember recent tables

- [feature] Remember the last sort order for each table

- [ajax] for Create table in navigation panel

- [feature] Wording about Column

- [ajax] AJAX for Add a user in Database privileges

- [feature] new DisableMultiTableMaintenance directive

- [interface] Reorganised server status page.

- [interface] Changed way of generating charts.

- [interface] Flexible column width

- [interface] Mouse-based column reordering in query results

- [ajax] AJAX for Insert to a table from database Structure page

- [patch] PMA_ajaxShowMessage() does not respect timeout

- [ajax] AJAX for Change on multiple rows in table Browse

- [interface] Improved support for stored routines

- [display] More options for browsing GIS data

- [interface] Support for spatial indexes

- [display] GIS data visualization

- [ajax] AJAX for table structure multiple-column change

- [ajax] AJAX for table structure index edit

- [feature] Show/hide indexes in table Structure

- [display] More compact navigation bar

- [display] Display direction (horizontal/vertical) no longer displayed by default

- [feature] Shift/click support in database Structure

- [display] Show/hide column in table Browse

- [ajax] AJAX dialogs use wrong font-size

- [interface] Timepicker does not work in AJAX dialogs

- [ajax] AJAX for table Structure Indexes Edit

- [ajax] AJAX for table Structure column Change

- [interface] Improved support for events

- [interface] Improved support for triggers

- [interface] Improved server monitoring

- [ajax] AJAX for table Structure column Add

- [ajax] AJAX for table Operations copy table

- [export] no uid Query result export (Suhosin limit)

- [feature] Grid editing in browse mode (replaces row inline edit)

- [feature] Zoom-search in table Search

- [interface] Editor for GIS data

- [import] Import GIS data from ESRI Shapefiles

- [interface] 'Function based search' for GIS data

- [database] Support Drizzle database

- [interface] Interface problems for queries having LIMIT clauses

- [interface] Remove DefaultPropDisplay feature

- [prettyprint] Order By in a query containing comment character

- [interface] Improved ENUM/SET editor

- [pmadb] pmadb on a different MySQL server

- [interface] Improving field size for character columns

- [usability] Removed an unnecessary AJAX request from database search

- [navi] Tabs break when squeezing page

- [navi] Stick table tools to top of page on scroll

- [interface] Improved error handling

- [interface] Add useful intermediate pages to pageselector

- [interface] Improved index editor

- [display] View editing via a generated ALTER VIEW

- [interface] Deleting table from the DB does not change the table counter

- [designer] Toggle for relation lines

- [ajax] database list not updated after adding/deleting a user + database

- [edit] Sort by key generates wrong sql with limit clause

- [structure] Error dropping index of non-existing column

- [display] Page through rows returned from a view

- [interface] Checkbox to have SQL input remain

- [export] Fixed CSV escape for the export

- [import] Fixed CSV escape for the import

- [interface] No warning on syntax error in search form

- [core] Improved detection of SSL connection

- [feature] FULLTEXT support for InnoDB, starting with MySQL 5.6.4

- [interface] Duplicate inline query edit box

- [mime] Description of the transformation missing in the tooltip

Changes for 3.4.11.0 (not yet released) :

- [import] Exception on XML import

- [navi] $cfg['ShowTooltipAliasTB'] and blank names in navigation

Changes for 3.4.10.2 (2012-03-28) :

- [security] Fixed local path disclosure vulnerability, see PMASA-2012-2

Changes for 3.4.10.1 (2012-02-18) :

- [security] XSS in replication setup, see PMASA-2012-1

Changes for 3.4.10.0 (2012-02-14) :

- [interface] TextareaAutoSelect feature broken

- [export] PHP Array export might generate invalid php code

- [import] Import from ODS ignores cell that is the same as cell before

- [display] SELECT DISTINCT displays wrong total records found

- [operations] copy table data missing SET SQL_MODE='NO_AUTO_VALUE_ON_ZERO'

- [edit] Setting data to NULL and drop-downs

- [edit] Missing set fields and values in generated INSERT query

- [libraries] license issue with TCPDF (updated to 5.9.145)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected phpMyAdmin package.

See Also

http://www.nessus.org/u?12e9095f

https://bugzilla.redhat.com/show_bug.cgi?id=795020

https://bugzilla.redhat.com/show_bug.cgi?id=809146

Plugin Details

Severity: Medium

ID: 58925

File Name: fedora_2012-5624.nasl

Version: 1.12

Type: local

Agent: unix

Published: 5/1/2012

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:phpmyadmin, cpe:/o:fedoraproject:fedora:16

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/11/2012

Vulnerability Publication Date: 4/6/2012

Reference Information

CVE: CVE-2012-1190, CVE-2012-1902

BID: 52857, 52858

FEDORA: 2012-5624