phpMyAdmin: Multiple vulnerabilities — GLSA 201311-02

Multiple vulnerabilities have been found in phpMyAdmin, allowing remote authenticated attackers to execute arbitrary code, inject SQL code or conduct other attacks.

Affected packages

dev-db/phpmyadmin on all architectures
Affected versions < 4.0.5
Unaffected versions >= 4.0.5

Background

phpMyAdmin is a web-based management tool for MySQL databases.

Description

Multiple vulnerabilities have been discovered in phpMyAdmin. Please review the CVE identifiers referenced below for details.

Impact

A remote authenticated attacker could exploit these vulnerabilities to execute arbitrary code with the privileges of the process running phpMyAdmin, inject SQL code, or to conduct Cross-Site Scripting and Clickjacking attacks.

Workaround

There is no known workaround at this time.

Resolution

All phpMyAdmin users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-4.0.5"
 

References

Release date
November 04, 2013

Latest revision
November 04, 2013: 1

Severity
normal

Exploitable
remote

Bugzilla entries