SB2016101829 - Security Features in phpmyadmin (Alpine package)



SB2016101829 - Security Features in phpmyadmin (Alpine package)

Published: October 18, 2016

Security Bulletin ID SB2016101829
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security Features (CVE-ID: CVE-2016-6624)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.


Remediation

Install update from vendor's website.