First published: Sat Feb 20 2016(Updated: )
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.1 | |
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 | |
phpMyAdmin | =4.0.0 | |
phpMyAdmin | =4.0.0-rc2 | |
phpMyAdmin | =4.0.0-rc3 | |
phpMyAdmin | =4.0.1 | |
phpMyAdmin | =4.0.10 | |
phpMyAdmin | =4.0.10.1 | |
phpMyAdmin | =4.0.10.2 | |
phpMyAdmin | =4.0.10.3 | |
phpMyAdmin | =4.0.10.4 | |
phpMyAdmin | =4.0.10.5 | |
phpMyAdmin | =4.0.10.6 | |
phpMyAdmin | =4.0.10.7 | |
phpMyAdmin | =4.0.10.8 | |
phpMyAdmin | =4.0.10.9 | |
phpMyAdmin | =4.0.10.10 | |
phpMyAdmin | =4.0.10.11 | |
phpMyAdmin | =4.0.10.12 | |
phpMyAdmin | =4.4.0 | |
phpMyAdmin | =4.4.1 | |
phpMyAdmin | =4.4.1.1 | |
phpMyAdmin | =4.4.2 | |
phpMyAdmin | =4.4.3 | |
phpMyAdmin | =4.4.4 | |
phpMyAdmin | =4.4.5 | |
phpMyAdmin | =4.4.6 | |
phpMyAdmin | =4.4.6.1 | |
phpMyAdmin | =4.4.7 | |
phpMyAdmin | =4.4.8 | |
phpMyAdmin | =4.4.9 | |
phpMyAdmin | =4.4.10 | |
phpMyAdmin | =4.4.11 | |
phpMyAdmin | =4.4.12 | |
phpMyAdmin | =4.4.13 | |
phpMyAdmin | =4.4.13.1 | |
phpMyAdmin | =4.4.14.1 | |
phpMyAdmin | =4.4.15 | |
phpMyAdmin | =4.4.15.1 | |
phpMyAdmin | =4.4.15.2 | |
phpMyAdmin | =4.4.15.3 | |
phpMyAdmin | =4.5.0 | |
phpMyAdmin | =4.5.0.1 | |
phpMyAdmin | =4.5.0.2 | |
phpMyAdmin | =4.5.1 | |
phpMyAdmin | =4.5.2 | |
phpMyAdmin | =4.5.3 | |
Fedora | =23 | |
Fedora | =24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2039 is classified as a medium severity vulnerability due to its ability to allow remote attackers to bypass access restrictions.
To fix CVE-2016-2039, update phpMyAdmin to versions 4.0.10.13 or later, 4.4.15.3 or later, or 4.5.4 or later.
CVE-2016-2039 affects phpMyAdmin versions 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4.
The impact of CVE-2016-2039 allows unauthorized access to sensitive functions by predicting CSRF token values.
Vulnerable systems include various versions of openSUSE and Fedora that run the affected versions of phpMyAdmin.