Red Hat Bugzilla – Bug 849007
CVE-2012-4219 phpMyAdmin: show_config_errors.php path disclosure flaw (PMASA-2012-3)
Last modified: 2014-11-07 06:53:30 EST
Path disclosure due to missing library.
The show_config_errors.php script does not include a library, so an error message shows the full path of this file, leading to possible further attacks.
We consider this vulnerability to be non critical.
For the error messages to be displayed, php.ini's error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual).
Versions 3.5.x before 184.108.40.206 are affected.
Upgrade to phpMyAdmin 220.127.116.11 or newer or apply the related patch listed below.