Fedora 23 : php-udan11-sql-parser-3.4.0-1.fc23 / phpMyAdmin-4.5.5.1-1.fc23 (2016-65da02b95c)

medium Nessus Plugin ID 89801

Synopsis

The remote Fedora host is missing one or more security updates.

Description

phpMyAdmin 4.5.5.1 (2016-02-29) =============================== This release fixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, and PMASA-2016-12 for details; additionally it fixes a vulnerability allowing man- in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details. It also inclues fixes for the following bugs: - issue #11971 CREATE UNIQUE INDEX index type is not recognized by parser. - issue #11982 Row count wrong when grouping joined tables. - issue #12012 Column definition with default value and comment in CREATE TABLE exported faulty. - issue #12020 New statement but no delimiter and unexpected token with REPLACE. - issue #12029 Fixed incorrect usage of SQL parser context in SQL export - issue #12048 Fixed inclusion of gettext library from SQL parser

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php-udan11-sql-parser and / or phpMyAdmin packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1313221

https://bugzilla.redhat.com/show_bug.cgi?id=1313224

https://bugzilla.redhat.com/show_bug.cgi?id=1313695

https://bugzilla.redhat.com/show_bug.cgi?id=1313696

http://www.nessus.org/u?5846dba5

http://www.nessus.org/u?5f797dc5

Plugin Details

Severity: Medium

ID: 89801

File Name: fedora_2016-65da02b95c.nasl

Version: 2.4

Type: local

Agent: unix

Published: 3/10/2016

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php-udan11-sql-parser, p-cpe:/a:fedoraproject:fedora:phpmyadmin, cpe:/o:fedoraproject:fedora:23

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 3/9/2016

Reference Information

CVE: CVE-2016-2559, CVE-2016-2560, CVE-2016-2561, CVE-2016-2562