Updated phpmyadmin packages fix security vulnerabilities
Publication date: 21 Jun 2019Modification date: 21 Jun 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2019-11768 , CVE-2019-12616
Description
Updated phpmyadmin packages fix security vulnerabilities:
A vulnerability was reported where a specially crafted database name can
be used to trigger an SQL injection attack through the designer feature.
(CVE-2019-11768, PMASA-2019-3)
A vulnerability was found that allows an attacker to trigger a CSRF attack
against a phpMyAdmin user. The attacker can trick the user, for instance
through a broken <img> tag pointing at the victim's phpMyAdmin database,
and the attacker can potentially deliver a payload (such as a specific
INSERT or DELETE statement) through the victim. (CVE-2019-12616,
PMASA-2019-4)
References
SRPMS
6/core
- phpmyadmin-4.7.8-5.mga6