Bug 989668 (CVE-2013-5003)

Summary: CVE-2013-5003 phpMyAdmin: SQL injection leading to 'control user' role privilege escalation (PMASA-2013-15)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ccoleman, dmcphers, jialiu, lmeyer, redhat-bugzilla, tkramer
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: phpMyAdmin 3.5.8.2, phpMyAdmin 4.0.4.2 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-09-07 05:19:21 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 989674, 989678, 989679, 989883    
Bug Blocks: 989687    

Description Jan Lieskovsky 2013-07-29 17:14:53 UTC
An SQL injection flaw, possibly leading to 'control user' role privilege escalation was found in the way phpMyAdmin, a tool written in PHP intended to handle the administration of MySQL over the World Wide Web, (previously) used to sanitize values of certain parameters passed to passed to selected table /storage engine content manipulation routines. A remote attacker could provide a specially-crafted web page that, when visited would lead to (attacker's) ability to inject arbitrary SQL, possibly leading into their ability to read / write tables of the configuration storage database, or read content of selected tables of the 'mysql' database.

Upstream advisory:
[1] http://www.phpmyadmin.net/home_page/security/PMASA-2013-15.php

Relevant patches:
* master:
    https://github.com/phpmyadmin/phpmyadmin/commit/974d0dedeea7c79ac4533e614d9c0c3abd97e8f9
    https://github.com/phpmyadmin/phpmyadmin/commit/8ef025ef3d05c164654fee7001517626cf604bb1
* 3.5.x:
    https://github.com/phpmyadmin/phpmyadmin/commit/4cbeef599cda87c6d2b1d7ef5542fe1ff316f706
    https://github.com/phpmyadmin/phpmyadmin/commit/20f71e767bcd037178cb5455543071323bc7ffd9

Comment 1 Jan Lieskovsky 2013-07-29 17:21:57 UTC
This issue affects the latest version of the phpMyAdmin package, as shipped with Fedora release of 18, 19, Fedora EPEL-6 and Fedora EPEL-5. Please schedule an update.

Comment 2 Jan Lieskovsky 2013-07-29 17:29:21 UTC
Created phpMyAdmin tracking bugs for this issue:

Affects: epel-5 [bug 989674]

Comment 3 Jan Lieskovsky 2013-07-29 17:39:05 UTC
Created phpMyAdmin tracking bugs for this issue:

Affects: fedora-all [bug 989678]
Affects: epel-6 [bug 989679]

Comment 5 Jan Lieskovsky 2013-07-30 09:06:16 UTC
The CVE identifier of CVE-2013-5003 has been assigned to this issue:
  http://www.openwall.com/lists/oss-security/2013/07/30/1

Comment 6 Fedora Update System 2014-07-30 07:00:59 UTC
phpMyAdmin-4.2.6-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2014-07-30 07:02:30 UTC
phpMyAdmin-4.2.6-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2014-08-07 11:46:06 UTC
phpMyAdmin-4.0.10.1-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2014-10-09 19:55:09 UTC
phpMyAdmin4-4.0.10.3-2.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.