Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200410-14] phpMyAdmin: Vulnerability in MIME-based transformation system


Vulnerability Assessment Details

[GLSA-200410-14] phpMyAdmin: Vulnerability in MIME-based transformation system

Vulnerability Assessment Summary
phpMyAdmin: Vulnerability in MIME-based transformation system

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200410-14
(phpMyAdmin: Vulnerability in MIME-based transformation system)


A defect was found in phpMyAdmin's MIME-based transformation system, when
used with "external" transformations.

Impact

A remote attacker could exploit this vulnerability to execute arbitrary
commands on the server with the rights of the HTTP server user.

Workaround

Enabling PHP safe mode ("safe_mode = On" in php.ini) may serve as a
temporary workaround.

References:
http://sourceforge.net/forum/forum.php?forum_id=414281
http://secunia.com/advisories/12813/


Solution:
All phpMyAdmin users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=dev-db/phpmyadmin-2.6.0_p2"
# emerge ">=dev-db/phpmyadmin-2.6.0_p2"


Network Security Threat Level: High


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2005 Michel Arboi

Cables, Connectors


NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK picture

NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK

$25.99



Everex disk drives for parts vintage NOT TESTED picture

Everex disk drives for parts vintage NOT TESTED

$39.99



Vintage Apple MacWorld Magazine Mousepad picture

Vintage Apple MacWorld Magazine Mousepad

$15.00



Vintage Logitech 3 Button Logimouse C7-3F-25F In Great Condition picture

Vintage Logitech 3 Button Logimouse C7-3F-25F In Great Condition

$10.00



Vintage Classic Apple Macintosh System Boot Install Disk Floppy/CD *Pick Version picture

Vintage Classic Apple Macintosh System Boot Install Disk Floppy/CD *Pick Version

$10.39



Vintage NEC MultiSpin 3XP External SCSI CD-ROM CDR-400 083A UNTESTED picture

Vintage NEC MultiSpin 3XP External SCSI CD-ROM CDR-400 083A UNTESTED

$44.99



Vintage ClarisWorks for Windows 1993 Brand New in Shrink Wrap picture

Vintage ClarisWorks for Windows 1993 Brand New in Shrink Wrap

$35.00



NEW Manufacture OLD STYLE Oval 3 Prong Power Cord HP style 125V 7A 875W Vintage picture

NEW Manufacture OLD STYLE Oval 3 Prong Power Cord HP style 125V 7A 875W Vintage

$39.95



VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS picture

VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS

$249.50



Vintage Apple Power Macintosh PC Computer M3979 7600/132 picture

Vintage Apple Power Macintosh PC Computer M3979 7600/132

$249.50



Discussions

No Discussions have been posted on this vulnerability.