Bug 824304 (CVE-2013-3240) - VUL-0: phpMyAdmin: CVE-2013-3240: Local file inclusion vulnerability.
Summary: VUL-0: phpMyAdmin: CVE-2013-3240: Local file inclusion vulnerability.
Status: RESOLVED FIXED
Alias: CVE-2013-3240
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-11 02:38 UTC by Alexander Bergmann
Modified: 2013-06-12 16:28 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2013-06-11 02:38:25 UTC
Public via PMASA-2013-4:

http://www.phpmyadmin.net/home_page/security/PMASA-2013-4.php

 PMASA-2013-4
 ------------

Announcement-ID: PMASA-2013-4

Date: 2013-04-24

Summary:

Local file inclusion vulnerability.

Description:

In the Export feature, a parameter specifying the export type was not correctly validated, opening the door to a local file inclusion attack.

Severity:

We consider this vulnerability to be serious.

Mitigation factor:

This vulnerability can be triggered only by someone who logged in to phpMyAdmin, as the usual token protection prevents non-logged-in users to access the required form.

Affected Versions:

phpMyAdmin versions 4.x (prior to 4.0.0-rc3).

Solution:

Upgrade to phpMyAdmin 4.0.0-rc3 or newer.

References:

Thanks to Janek Vind for reporting this issue.

Assigned CVE ids: CVE-2013-3240
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3240

CWE ids: CWE-661 CWE-98 
http://cwe.mitre.org/data/definitions/661.html
http://cwe.mitre.org/data/definitions/98.html
Comment 1 Swamp Workflow Management 2013-06-11 16:00:35 UTC
bugbot adjusting priority
Comment 2 Christian Wittmer 2013-06-12 16:24:32 UTC
fixed with update to 4.0.3
Comment 3 Christian Wittmer 2013-06-12 16:28:51 UTC
fixed with update to 4.0.3