Bug 989657 (CVE-2013-4996, CVE-2013-4997)
Summary: | CVE-2013-4996 CVE-2013-4997 phpMyAdmin: Multiple (of both types, reflected and stored) XSS in various components (PMASA-2013-9 and PMASA-2013-11) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | ccoleman, dmcphers, jialiu, lmeyer, redhat-bugzilla, tkramer |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | phpMyAdmin 3.5.8.2, phpMyAdmin 4.0.4.2 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-09-07 05:17:43 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 989678, 989679, 989878 | ||
Bug Blocks: | 989687 |
Description
Jan Lieskovsky
2013-07-29 17:07:46 UTC
This issue affects the latest version of the phpMyAdmin package, as shipped with Fedora release of 18, 19, and Fedora EPEL 6. Please schedule an update. -- This issue did not affect the latest version of the phpMyAdmin package, as shipped with Fedora EPEL-5. Created phpMyAdmin tracking bugs for this issue: Affects: fedora-all [bug 989678] Affects: epel-6 [bug 989679] Based on: http://www.openwall.com/lists/oss-security/2013/07/30/1 the CVE identifiers for PMASA-2013-9 and PMASA-2013-11 advisories have been assigned as follows: "Use CVE-2013-4996 for the PMASA-2013-9 XSS issues that affect both 3.5.x and 4.0.x, and for the PMASA-2013-11 XSS issue. Use CVE-2013-4997 for the PMASA-2013-9 XSS issues that affect only 3.5.x. (We think this may be the first two issues, but the CVE is assigned on the basis of affected versions, not the vulnerability details.) (We didn't notice any XSS issues that affected only 4.0.x.)" *** Bug 989658 has been marked as a duplicate of this bug. *** |