An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | mailing list |
https://www.phpmyadmin.net/security/PMASA-2016-70 | patch vendor advisory |
http://www.securityfocus.com/bid/94531 | vdb entry |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |