CVE-2013-3239
Description
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-3239
Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/1f6bc0b707002e26cab216b9e57b4d5de764de48
Vendor advisory: cve@mitre.org — http://www.phpmyadmin.net/home_page/security/PMASA-2013-3.php
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4:3.4.11.1-2 |
| debian | bullseye | fixed | 4:3.4.11.1-2 |
| debian | sid | fixed | 4:3.4.11.1-2 |
| debian | trixie | fixed | 4:3.4.11.1-2 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | phpmyadmin/phpmyadmin | >=3.5.0,<3.5.8.1 | 3.5.8.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| phpmyadmin | phpmyadmin | 3.5.0.0 | |
| phpmyadmin | phpmyadmin | 3.5.1.0 | |
| phpmyadmin | phpmyadmin | 3.5.2.0 | |
| phpmyadmin | phpmyadmin | 3.5.2.1 | |
| phpmyadmin | phpmyadmin | 3.5.2.2 | |
| phpmyadmin | phpmyadmin | 3.5.3.0 | |
| phpmyadmin | phpmyadmin | 3.5.4 | |
| phpmyadmin | phpmyadmin | 3.5.5 | |
| phpmyadmin | phpmyadmin | 3.5.6 | |
| phpmyadmin | phpmyadmin | 3.5.7 | |
| phpmyadmin | phpmyadmin | 3.5.8 | |
| phpmyadmin | phpmyadmin | 4.0.0 | |
References
- http://archives.neohapsis.com/archives/bugtraq/2013-04/0217.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104725.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104770.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104936.html
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00181.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:160
- http://www.phpmyadmin.net/home_page/security/PMASA-2013-3.php
- https://github.com/phpmyadmin/phpmyadmin/commit/1f6bc0b707002e26cab216b9e57b4d5de764de48
- https://github.com/phpmyadmin/phpmyadmin/commit/d3fafdfba0807068196655e9b6d16c5d1d3ccf8a
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0133
- https://nvd.nist.gov/vuln/detail/CVE-2013-3239
- https://github.com/phpmyadmin/phpmyadmin
- https://security-tracker.debian.org/tracker/CVE-2013-3239
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.