Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2016.757
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-757-1)
Summary:The remote host is missing an update for the Debian 'phpmyadmin' package(s) announced via the DLA-757-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'phpmyadmin' package(s) announced via the DLA-757-1 advisory.

Vulnerability Insight:
Various security issues where found and fixed in phpmyadmin in wheezy.

CVE-2016-4412 / PMASA-2016-57 A user can be tricked in following a link leading to phpMyAdmin, which after authentication redirects to another malicious site.

CVE-2016-6626 / PMASA-2016-49 In the fix for PMASA-2016-57, we didn't have sufficient checking and was possible to bypass whitelist.

CVE-2016-9849 / PMASA-2016-60 Username deny rules bypass (AllowRoot & Others) by using Null Byte.

CVE-2016-9850 / PMASA-2016-61 Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time.

CVE-2016-9861 / PMASA-2016-66 In the fix for PMASA-2016-49, we has buggy checks and was possible to bypass whitelist.

CVE-2016-9864 / PMASA-2016-69 Multiple SQL injection vulnerabilities.

CVE-2016-9865 / PMASA-2016-70 Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function.

For Debian 7 Wheezy, these problems have been fixed in version 4:3.4.11.1-2+deb7u7.

We recommend that you upgrade your phpmyadmin packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'phpmyadmin' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-4412
BugTraq ID: 94519
http://www.securityfocus.com/bid/94519
https://security.gentoo.org/glsa/201701-32
Common Vulnerability Exposure (CVE) ID: CVE-2016-6626
BugTraq ID: 92490
http://www.securityfocus.com/bid/92490
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9849
BugTraq ID: 94521
http://www.securityfocus.com/bid/94521
Common Vulnerability Exposure (CVE) ID: CVE-2016-9850
BugTraq ID: 94529
http://www.securityfocus.com/bid/94529
Common Vulnerability Exposure (CVE) ID: CVE-2016-9861
BugTraq ID: 94535
http://www.securityfocus.com/bid/94535
Common Vulnerability Exposure (CVE) ID: CVE-2016-9864
BugTraq ID: 94533
http://www.securityfocus.com/bid/94533
Common Vulnerability Exposure (CVE) ID: CVE-2016-9865
BugTraq ID: 94531
http://www.securityfocus.com/bid/94531
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.