Bug 902154 (CVE-2014-8326) - VUL-0: phpMyAdmin: XSS vulnerabilities in SQL debug output and server monitor page.
Summary: VUL-0: phpMyAdmin: XSS vulnerabilities in SQL debug output and server monito...
Status: RESOLVED FIXED
Alias: CVE-2014-8326
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: 13.2 RC 1
Hardware: Other Other
: P4 - Low : Minor (vote)
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: E-mail List
URL: http://www.phpmyadmin.net/home_page/s...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-10-21 22:55 UTC by Andreas Stieger
Modified: 2014-11-20 19:52 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2014-10-21 22:55:44 UTC
http://www.phpmyadmin.net/home_page/news.php#phpMyAdmin_4.0.10.5__4.1.14.6_and_4.2.10.1_are_released

Tue, 21 Oct 2014 14:50:14 GMT

Welcome to phpMyAdmin 4.0.10.5, 4.1.14.6 and 4.2.10.1, which contain security fixes.

http://www.phpmyadmin.net/home_page/security/PMASA-2014-12.php

Announcement-ID: PMASA-2014-12

Date: 2014-10-21
Summary: XSS vulnerabilities in SQL debug output and server monitor page.

With a crafted database or table name it is possible to trigger an XSS in SQL debug output when enabled and in server monitor page when viewing and analysing executed queries.
Severity

Considered non-critical.
Logged in user required.
Developer option, disabled by default, expected to be disabled in production environments.

affects 4.0.x (prior to 4.0.10.5)
affects 4.1.x (prior to 4.1.14.6) - openSUSE:13.1:Update, openSUSE:12.3:Update 4.1.14.5
affects 4.2.x (prior to 4.2.10.1) - openSUSE:13.2 4.2.9.1
Comment 1 Andreas Stieger 2014-10-21 23:39:55 UTC
SR to openSUSE:Factory:
https://build.opensuse.org/request/show/257927

MR for 12.3 and 13.1:
https://build.opensuse.org/request/show/257928

MR for 13.2:
https://build.opensuse.org/request/show/257930
Comment 2 Swamp Workflow Management 2014-11-03 12:04:55 UTC
openSUSE-SU-2014:1347-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 902154
CVE References: CVE-2014-8326
Sources used:
openSUSE 13.1 (src):    phpMyAdmin-4.1.14.6-20.1
openSUSE 12.3 (src):    phpMyAdmin-4.1.14.6-1.28.1
Comment 3 Andreas Stieger 2014-11-20 19:52:01 UTC
Updates released for 12.3 and 13.1.
13.2 was release with 4.2.10.1.