UbuntuUpdates.org

Package "phpmyadmin"

Name: phpmyadmin

Description:

MySQL web administration tool

Latest version: 4:4.0.10-1ubuntu0.1
Release: trusty (14.04)
Level: security
Repository: universe
Homepage: http://www.phpmyadmin.net/

Links


Download "phpmyadmin"


Other versions of "phpmyadmin" in Trusty

Repository Area Version
base universe 4:4.0.10-1
updates universe 4:4.0.10-1ubuntu0.1

Changelog

Version: 4:4.0.10-1ubuntu0.1 2018-08-30 20:06:37 UTC

  phpmyadmin (4:4.0.10-1ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Username/password decryption; Remote command execution
    - debian/patches/CVE-2016-6606-1.patch: Improve cookie encryption
    - debian/patches/CVE-2016-6606-2.patch: Use hash_equals for comparing
      token
    - debian/patches/CVE-2016-6631.patch: Move generator scripts out of the
      code
    - CVE-2016-6606, CVE-2016-6631

 -- Mike Salvatore <email address hidden> Wed, 29 Aug 2018 14:43:10 -0400

CVE-2016-6606 An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca
CVE-2016-6631 An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI appli



About   -   Send Feedback to @ubuntu_updates