PT-2016-5209 · Phpmyadmin · Phpmyadmin

Publicado

2016-03-01

·

Atualizado

2024-06-15

·

CVE-2016-2562

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.5.x through 4.5.5.0
Description The issue concerns the checkHTTP function in the Config.class.php file, which fails to verify X.509 certificates from SSL servers, specifically those from api.github.com. This oversight allows man-in-the-middle attackers to spoof these servers, potentially obtaining sensitive information by using a crafted certificate.
Recommendations For phpMyAdmin versions 4.5.x through 4.5.5.0, update to version 4.5.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the checkHTTP function until a patch is available. Restrict access to the Config.class.php file to minimize the risk of exploitation. Avoid using the checkHTTP function for verifying SSL connections until the issue is resolved.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-2562
GHSA-W8QG-J9FP-HRJF
OPENSUSE-SU-2024:10054-1

Produtos afetados

Phpmyadmin