Fedora 9 : phpMyAdmin- (2008-6868)

Medium Nessus Plugin ID 33769


The remote Fedora host is missing a security update.


This update solves PMASA-2008-6 (phpMyAdmin security announcement) from 2008-07-28: Cross-site Framing; XSS in setup.php; see http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-6 - [interface] Table list pagination in navi - [profiling] Profiling causes query to be executed again (really causes a problem in case of INSERT/UPDATE) - [import] SQL file import very slow on Windows - [XHTML] problem with tabindex and radio fields - [interface] tabindex not set correctly - [views] VIEW name created via the GUI was not protected with backquotes - [interface] Deleting multiple views (space in name) - [parser] SQL parser removes essential space - [export] CSV for MS Excel incorrect escaping of double quotes - [interface] Font size option problem when no config file - [relation] Relationship view should check for changes - [history] Do not save too big queries in history - [security] Do not show version info on login screen - [import] Potential data loss on import resubmit - [export] Safari and timedate - [import, export] Import/Export fails because of Mac files - [security] protection against cross- frame scripting and new directive AllowThirdPartyFraming - [security] possible XSS during setup - [interface] revert language changing problem introduced with phpMyAdmin is a bugfix-only version containing normal bug fixes and two security fixes. This version is identical to 2.11.8, except it includes a fix for a notice about 'lang'.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected phpMyAdmin package.

See Also




Plugin Details

Severity: Medium

ID: 33769

File Name: fedora_2008-6868.nasl

Version: $Revision: 1.12 $

Type: local

Agent: unix

Published: 2008/07/31

Modified: 2016/12/08

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.4

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:phpMyAdmin, cpe:/o:fedoraproject:fedora:9

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/07/30

Reference Information

CVE: CVE-2008-3456, CVE-2008-3457

BID: 30420

FEDORA: 2008-6868

CWE: 59, 79