An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92492 | third party advisory vdb entry |
https://www.phpmyadmin.net/security/PMASA-2016-51 | patch vendor advisory |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html | mailing list |