Bug 849007 - (CVE-2012-4219) CVE-2012-4219 phpMyAdmin: show_config_errors.php path disclosure flaw (PMASA-2012-3)
CVE-2012-4219 phpMyAdmin: show_config_errors.php path disclosure flaw (PMASA-...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20120809,reported=2...
: Security
Depends On: 849010
Blocks:
  Show dependency treegraph
 
Reported: 2012-08-17 00:02 EDT by Kurt Seifried
Modified: 2014-11-07 06:53 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-07-19 11:50:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Kurt Seifried 2012-08-17 00:02:55 EDT
phpMyAdmin reports:

Summary

Path disclosure due to missing library.
Description

The show_config_errors.php script does not include a library, so an error message shows the full path of this file, leading to possible further attacks.
Severity

We consider this vulnerability to be non critical.
Mitigation factor

For the error messages to be displayed, php.ini's error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual).
Affected Versions

Versions 3.5.x before 3.5.2.1 are affected.
Solution

Upgrade to phpMyAdmin 3.5.2.1 or newer or apply the related patch listed below.

External References:

http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php

Note You need to log in before you can comment on or make changes to this bug.