Bug 993613 (CVE-2013-5029)

Summary: CVE-2013-5029 phpMyAdmin: ClickJacking protection can be bypassed (PMASA-2013-10)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ccoleman, dmcphers, jialiu, lmeyer, redhat-bugzilla, tdawson, tkramer
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: phpMyAdmin-4.0.5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-09-07 05:19:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 993617, 993618, 998644    
Bug Blocks: 993620    

Description Jan Lieskovsky 2013-08-06 09:44:06 UTC
A security flaw was found in the way phpMyAdmin, a tool to handle the administration of MySQL over the World Wide Web, (previously) implemented the protection against the click-jacking attacks. A remote attacker could provide a specially-crafted web page that, when visited by an unsuspecting phpMyAdmin user might allow an attacker to perform some kind of unauthorized action.

Upstream advisory:
[1] http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php

Relevant patches [*]
[2] https://github.com/phpmyadmin/phpmyadmin/commit/240b8332db53dedc27baeec5306dabad3bdece3b
[3] https://github.com/phpmyadmin/phpmyadmin/commit/24d0eb55203b029f250c77d63f2900ffbe099e8b
[4] https://github.com/phpmyadmin/phpmyadmin/commit/66fe475d4f51b1761719cb0cab360748800373f7
[5] https://github.com/phpmyadmin/phpmyadmin/commit/da4042fb6c4365dc8187765c3bf525043687c66f

--
[*] Though for phpMyAdmin versions of 3.5.x upstream suggests to upgrade to version 4.0.5 or newer due the complexity of introducing the dependency on JavaScript in 3.5.x version.

Comment 1 Jan Lieskovsky 2013-08-06 09:46:47 UTC
This issue affects the (latest) versions of the phpMyAdmin package, as shipped with Fedora release of 18, 19, Fedora EPEL-5, and Fedora EPEL-6. Please schedule an update.

Comment 2 Jan Lieskovsky 2013-08-06 09:48:03 UTC
Created phpMyAdmin tracking bugs for this issue:

Affects: fedora-all [bug 993617]
Affects: epel-all [bug 993618]

Comment 4 Fedora Update System 2014-07-30 07:01:01 UTC
phpMyAdmin-4.2.6-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2014-07-30 07:02:33 UTC
phpMyAdmin-4.2.6-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2014-08-07 11:46:09 UTC
phpMyAdmin-4.0.10.1-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.