Bugzilla (bugzilla.redhat.com) will be under maintenance for infrastructure upgrades and will not be unavailable on July 31st between 12:30 AM - 05:30 AM UTC. We appreciate your understanding and patience. You can follow status.redhat.com for details.
Bug 808439 (CVE-2012-1600) - CVE-2012-1600 phpPgAdmin: XSS by displaying default list of functions in the database
Summary: CVE-2012-1600 phpPgAdmin: XSS by displaying default list of functions in the ...
Keywords:
Status: NEW
Alias: CVE-2012-1600
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-03-30 11:39 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:51 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Jan Lieskovsky 2012-03-30 11:39:00 UTC
An cross-site scripting (XSS) flaw was found in the way phpPgAdmin, a web-based PostgreSQL database administration tool, performed presentation of the default list of functions, being present in the database, to the user upon request. A remote attacker could provide a specially-crafted web page, which once visited by an unsuspecting, valid phpPgAdmin user could lead to arbitrary HTML or web script execution in the context of logged in phpPgAdmin user.

References:
[1] http://archives.postgresql.org/pgsql-announce/2012-03/msg00016.php
[2] https://github.com/phppgadmin/phppgadmin/commit/e92a003624609a445c4cf57c9c3d1fcef0eae47c#diff-0

Upstream patch:
[3] https://github.com/phppgadmin/phppgadmin/commit/74174ad639664b52cc1609ede0af8bc403e98a00

CVE request:
[4] http://www.openwall.com/lists/oss-security/2012/03/28/11

CVE assignment:
[5] http://www.openwall.com/lists/oss-security/2012/03/29/6

Comment 1 Jan Lieskovsky 2012-03-30 11:43:49 UTC
This issue previously affected the versions of the phpPgAdmin package, as shipped with Fedora release of 15, 16, and as shipped with Fedora EPEL 5 and Fedora EPEL 6 versions.

Though the following phpPgAdmin have been scheduled already:
1) phpPgAdmin-5.0.4-1.fc15 for Fedora 15,
2) phpPgAdmin-5.0.4-1.fc16 for Fedora 16,
3) phpPgAdmin-5.0.4-1.el5  for Fedora EPEL 5,
4) phpPgAdmin-5.0.4-1.el6  for Fedora EPEL 6

to correct this deficiency. Once the above packages have passed the required level of testing, they will be pushed to the -stable repository for each of the particular releases above.


Note You need to log in before you can comment on or make changes to this bug.