Published: 19-01-2010
Updated: 28-01-2010
Product:
phpmyadmin: phpmyadmin 2.11.0
phpmyadmin: phpmyadmin 2.11.0
phpmyadmin: phpmyadmin 2.11.0.0
phpmyadmin: phpmyadmin 2.11.0beta1
phpmyadmin: phpmyadmin 2.11.0rc1
phpmyadmin: phpmyadmin 2.11.1
phpmyadmin: phpmyadmin 2.11.1.0
phpmyadmin: phpmyadmin 2.11.1.1
phpmyadmin: phpmyadmin 2.11.1.2
phpmyadmin: phpmyadmin 2.11.1rc1
phpmyadmin: phpmyadmin 2.11.2
phpmyadmin: phpmyadmin 2.11.2.0
phpmyadmin: phpmyadmin 2.11.2.1
phpmyadmin: phpmyadmin 2.11.2.2
phpmyadmin: phpmyadmin 2.11.3
phpmyadmin: phpmyadmin 2.11.3.0
phpmyadmin: phpmyadmin 2.11.3rc1
phpmyadmin: phpmyadmin 2.11.4
phpmyadmin: phpmyadmin 2.11.4.0
phpmyadmin: phpmyadmin 2.11.4rc1
phpmyadmin: phpmyadmin 2.11.5
phpmyadmin: phpmyadmin 2.11.5.0
phpmyadmin: phpmyadmin 2.11.5.1
phpmyadmin: phpmyadmin 2.11.5.2
phpmyadmin: phpmyadmin 2.11.5rc1
phpmyadmin: phpmyadmin 2.11.6
phpmyadmin: phpmyadmin 2.11.6.0
phpmyadmin: phpmyadmin 2.11.6rc1
phpmyadmin: phpmyadmin 2.11.7
phpmyadmin: phpmyadmin 2.11.7.0
phpmyadmin: phpmyadmin 2.11.7.12.11.7.1
phpmyadmin: phpmyadmin 2.11.8
phpmyadmin: phpmyadmin 2.11.9
phpmyadmin: phpmyadmin 2.11.9.0
phpmyadmin: phpmyadmin 2.11.9.1
phpmyadmin: phpmyadmin 2.11.9.2
phpmyadmin: phpmyadmin 2.11.9.3
phpmyadmin: phpmyadmin 2.11.9.4
phpmyadmin: phpmyadmin 2.11.9.5
phpmyadmin: phpmyadmin 2.11.9.6
Severity: High (7.5)
CVSS vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Potential loss type: Integrity, Confidentiality, Availability
Vulnerability description:
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.
Patch available: Yes
References:
BID: http://www.securityfocus.com/bid/37826
CONFIRM: http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php
SECUNIA: http://secunia.com/advisories/38211
CONFIRM: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revis ...
CONFIRM: http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/QA_2_ ...
SUSE: http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007. ...
