Description: | Summary: The remote host is missing an update for the Debian 'phpmyadmin' package(s) announced via the DSA-3382-1 advisory.
Vulnerability Insight: Several issues have been fixed in phpMyAdmin, the web administration tool for MySQL.
CVE-2014-8958 (Wheezy only) Multiple cross-site scripting (XSS) vulnerabilities.
CVE-2014-9218 (Wheezy only) Denial of service (resource consumption) via a long password.
CVE-2015-2206
Risk of BREACH attack due to reflected parameter.
CVE-2015-3902
XSRF/CSRF vulnerability in phpMyAdmin setup.
CVE-2015-3903 (Jessie only) Vulnerability allowing man-in-the-middle attack on API call to GitHub.
CVE-2015-6830 (Jessie only) Vulnerability that allows bypassing the reCaptcha test.
CVE-2015-7873 (Jessie only) Content spoofing vulnerability when redirecting user to an external site.
For the oldstable distribution (wheezy), these problems have been fixed in version 4:3.4.11.1-2+deb7u2.
For the stable distribution (jessie), these problems have been fixed in version 4:4.2.12-2+deb8u1.
For the unstable distribution (sid), these problems have been fixed in version 4:4.5.1-1.
We recommend that you upgrade your phpmyadmin packages.
Affected Software/OS: 'phpmyadmin' package(s) on Debian 7, Debian 8.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
|