CVE-2016-6629
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6629
Vendor advisory: cve@mitre.org — https://www.phpmyadmin.net/security/PMASA-2016-52
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4:4.6.4+dfsg1-1 |
| debian | bullseye | fixed | 4:4.6.4+dfsg1-1 |
| debian | sid | fixed | 4:4.6.4+dfsg1-1 |
| debian | trixie | fixed | 4:4.6.4+dfsg1-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | phpmyadmin/phpmyadmin | >=4.6,<4.6.4 | 4.6.4 |
| Packagist | phpmyadmin/phpmyadmin | >=4.4,<4.4.15.8 | 4.4.15.8 |
| Packagist | phpmyadmin/phpmyadmin | >=4.0,<4.0.10.17 | 4.0.10.17 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| phpmyadmin | phpmyadmin | 4.6.0 | |
| phpmyadmin | phpmyadmin | 4.6.1 | |
| phpmyadmin | phpmyadmin | 4.6.2 | |
| phpmyadmin | phpmyadmin | 4.6.3 | |
| phpmyadmin | phpmyadmin | 4.0.0 | |
| phpmyadmin | phpmyadmin | 4.0.1 | |
| phpmyadmin | phpmyadmin | 4.0.2 | |
| phpmyadmin | phpmyadmin | 4.0.3 | |
| phpmyadmin | phpmyadmin | 4.0.4 | |
| phpmyadmin | phpmyadmin | 4.0.4.1 | |
| phpmyadmin | phpmyadmin | 4.0.4.2 | |
| phpmyadmin | phpmyadmin | 4.0.5 | |
| phpmyadmin | phpmyadmin | 4.0.6 | |
| phpmyadmin | phpmyadmin | 4.0.7 | |
| phpmyadmin | phpmyadmin | 4.0.8 | |
| phpmyadmin | phpmyadmin | 4.0.9 | |
| phpmyadmin | phpmyadmin | 4.0.10 | |
| phpmyadmin | phpmyadmin | 4.0.10.1 | |
| phpmyadmin | phpmyadmin | 4.0.10.2 | |
| phpmyadmin | phpmyadmin | 4.0.10.3 | |
| phpmyadmin | phpmyadmin | 4.0.10.4 | |
| phpmyadmin | phpmyadmin | 4.0.10.5 | |
| phpmyadmin | phpmyadmin | 4.0.10.6 | |
| phpmyadmin | phpmyadmin | 4.0.10.7 | |
| phpmyadmin | phpmyadmin | 4.0.10.8 | |
| phpmyadmin | phpmyadmin | 4.0.10.9 | |
| phpmyadmin | phpmyadmin | 4.0.10.10 | |
| phpmyadmin | phpmyadmin | 4.0.10.11 | |
| phpmyadmin | phpmyadmin | 4.0.10.12 | |
| phpmyadmin | phpmyadmin | 4.0.10.13 | |
| phpmyadmin | phpmyadmin | 4.0.10.14 | |
| phpmyadmin | phpmyadmin | 4.0.10.15 | |
| phpmyadmin | phpmyadmin | 4.0.10.16 | |
| phpmyadmin | phpmyadmin | 4.4.0 | |
| phpmyadmin | phpmyadmin | 4.4.1 | |
| phpmyadmin | phpmyadmin | 4.4.1.1 | |
| phpmyadmin | phpmyadmin | 4.4.2 | |
| phpmyadmin | phpmyadmin | 4.4.3 | |
| phpmyadmin | phpmyadmin | 4.4.4 | |
| phpmyadmin | phpmyadmin | 4.4.5 | |
| phpmyadmin | phpmyadmin | 4.4.6 | |
| phpmyadmin | phpmyadmin | 4.4.6.1 | |
| phpmyadmin | phpmyadmin | 4.4.7 | |
| phpmyadmin | phpmyadmin | 4.4.8 | |
| phpmyadmin | phpmyadmin | 4.4.9 | |
| phpmyadmin | phpmyadmin | 4.4.10 | |
| phpmyadmin | phpmyadmin | 4.4.11 | |
| phpmyadmin | phpmyadmin | 4.4.12 | |
| phpmyadmin | phpmyadmin | 4.4.13 | |
| phpmyadmin | phpmyadmin | 4.4.13.1 | |
| phpmyadmin | phpmyadmin | 4.4.14 | |
| phpmyadmin | phpmyadmin | 4.4.14.1 | |
| phpmyadmin | phpmyadmin | 4.4.15 | |
| phpmyadmin | phpmyadmin | 4.4.15.1 | |
| phpmyadmin | phpmyadmin | 4.4.15.2 | |
| phpmyadmin | phpmyadmin | 4.4.15.3 | |
| phpmyadmin | phpmyadmin | 4.4.15.4 | |
| phpmyadmin | phpmyadmin | 4.4.15.5 | |
| phpmyadmin | phpmyadmin | 4.4.15.6 | |
| phpmyadmin | phpmyadmin | 4.4.15.7 | |
References
- http://www.securityfocus.com/bid/92493
- https://security.gentoo.org/glsa/201701-32
- https://www.phpmyadmin.net/security/PMASA-2016-52
- https://nvd.nist.gov/vuln/detail/CVE-2016-6629
- https://web.archive.org/web/20210725054025/http://www.securityfocus.com/bid/92493
- https://security-tracker.debian.org/tracker/CVE-2016-6629
CWEs
CWE-254
Verify integrity in audit chain (admin only). AS-IS.