MGASA-2014-0495
Dashboard / Vulnerabilities / MGASA-2014-0495
MGASA-2014-0495
Summary: Updated phpmyadmin packages fix security vulnerabilities
Details: Updated phpmyadmin package fixes security vulnerabilities: In phpMyAdmin before 4.1.14.7, with a crafted database, table or column name it is possible to trigger an XSS attack in the table browse page, with a crafted ENUM value it is possible to trigger XSS attacks in the table print view and zoom search pages, and with a crafted value for font size it is possible to trigger an XSS attack in the home page (CVE-2014-8958). In phpMyAdmin before 4.1.14.7, in the GIS editor feature, a parameter specifying the geometry type was not correcly validated, opening the door to a local file inclusion attack (CVE-2014-8959). In phpMyAdmin before 4.1.14.7, with a crafted file name it is possible to trigger an XSS in the error reporting page (CVE-2014-8960). In phpMyAdmin before 4.1.14.7, in the error reporting feature, a parameter specifying the file was not correctly validated, allowing the attacker to derive the line count of an arbitrary file (CVE-2014-8961).
References: https://advisories.mageia.org/MGASA-2014-0495.html, https://bugs.mageia.org/show_bug.cgi?id=14637, http://www.phpmyadmin.net/home_page/security/PMASA-2014-13.php, http://www.phpmyadmin.net/home_page/security/PMASA-2014-14.php, http://www.phpmyadmin.net/home_page/security/PMASA-2014-15.php, http://www.phpmyadmin.net/home_page/security/PMASA-2014-16.php
Affected packages
Package
Name: phpmyadmin
Purl: pkg:rpm/mageia/phpmyadmin?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
