Description: | Description: The remote host is missing an update to phpMyAdmin announced via advisory FEDORA-2011-9734.
Update Information:
Changes for 3.4.3.2 (2011-07-23)
* [PMASA-2011-9] XSS in table Print view (http://www.phpmyadmin.net/home_page/security/PMASA-2011-9.php) * [PMASA-2011-10] Local file inclusion via a crafted MIME-type transformation parameter (http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php) * [PMASA-2011-11] Local file inclusion vulnerability and code execution (http://www.phpmyadmin.net/home_page/security/PMASA-2011-11.php) * [PMASA-2011-12] Possible superglobal and local variables manipulation in swekey authentication (http://www.phpmyadmin.net/home_page/security/PMASA-2011-12.php)
References:
[ 1 ] Bug #725381 - CVE-2011-2642 phpMyAdmin: v3.3.10.3, v3.4.3.2: XSS in table Print view (PMASA-2011-9) https://bugzilla.redhat.com/show_bug.cgi?id=725381 [ 2 ] Bug #725382 - CVE-2011-2643 phpMyAdmin: v3.3.10.3, v3.4.3.2: Local file inclusion via a crafted MIME-type transformation parameter (PMASA-2011-10) https://bugzilla.redhat.com/show_bug.cgi?id=725382 [ 3 ] Bug #725383 - CVE-2011-2718 phpMyAdmin: v3.3.10.3, v3.4.3.2: Local file inclusion and code execution in 'relational schema' code (PMASA-2011-11) https://bugzilla.redhat.com/show_bug.cgi?id=725383 [ 4 ] Bug #725384 - CVE-2011-2719 phpMyAdmin: v3.3.10.3, v3.4.3.2: Possible session manipulation in Swekey extention authentication (PMASA-2011-12) https://bugzilla.redhat.com/show_bug.cgi?id=725384
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update phpMyAdmin' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-9734
Risk factor : High
CVSS Score: 6.8
|