An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://www.phpmyadmin.net/security/PMASA-2016-61 | patch vendor advisory |
http://www.securityfocus.com/bid/94529 | vdb entry third party advisory |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html | mailing list |