Bug 824305 (CVE-2013-3241) - VUL-0: phpMyAdmin: CVE-2013-3241: Global variables overwrite in "export.php".
Summary: VUL-0: phpMyAdmin: CVE-2013-3241: Global variables overwrite in "export.php".
Status: RESOLVED FIXED
Alias: CVE-2013-3241
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-11 02:38 UTC by Alexander Bergmann
Modified: 2013-06-12 16:29 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2013-06-11 02:38:31 UTC
Public via PMASA-2013-5.

http://www.phpmyadmin.net/home_page/security/PMASA-2013-5.php

 PMASA-2013-5
 ------------

Announcement-ID: PMASA-2013-5

Date: 2013-04-24

Summary:

Global variables overwrite in "export.php".

Description:

The export script generates global variables from those present in the $_POST superglobal. This may lead to other exploits in the export script.

Severity:

We consider this vulnerability to be serious.

Mitigation factor:

This vulnerability can be triggered only by someone who logged in to phpMyAdmin, as the usual token protection prevents non-logged-in users to access the required form.

Affected Versions:

phpMyAdmin versions 4.x (prior to 4.0.0-rc3).

Solution:

Upgrade to phpMyAdmin 4.0.0-rc3 or newer.

References:

Thanks to Janek Vind for reporting this issue.

Assigned CVE ids: CVE-2013-3241
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3241

CWE ids: CWE-661 
http://cwe.mitre.org/data/definitions/661.html
Comment 1 Swamp Workflow Management 2013-06-11 16:00:40 UTC
bugbot adjusting priority
Comment 2 Christian Wittmer 2013-06-12 16:25:44 UTC
fixed with update to 4.0.3
Comment 3 Christian Wittmer 2013-06-12 16:29:07 UTC
fixed with update to 4.0.3