libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-updates/2016-02/msg00049.html | third party advisory vendor advisory |
http://www.debian.org/security/2016/dsa-3627 | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2016-02/msg00028.html | third party advisory vendor advisory |
http://www.phpmyadmin.net/home_page/security/PMASA-2016-5.php | patch vendor advisory |
https://github.com/phpmyadmin/phpmyadmin/commit/ec0e88e37ef30a66eada1c072953f4ec385a3e49 | patch |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176739.html | third party advisory vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176483.html | third party advisory vendor advisory |