CVE-2016-5739: Infoleak
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5739?
The severity of CVE-2016-5739 is classified as medium due to its potential for cross-site request forgery (CSRF) attacks.
How do I fix CVE-2016-5739?
To fix CVE-2016-5739, upgrade phpMyAdmin to version 4.0.10.16 or later, 4.4.15.7 or later, or 4.6.3 or later.
Which versions of phpMyAdmin are affected by CVE-2016-5739?
CVE-2016-5739 affects phpMyAdmin versions 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3.
What types of attacks can CVE-2016-5739 facilitate?
CVE-2016-5739 can facilitate cross-site request forgery (CSRF) attacks, allowing remote attackers to exploit authentication tokens.
Are any specific operating systems affected by CVE-2016-5739?
Yes, CVE-2016-5739 affects specific versions of openSUSE, including Leap 42.1 and OpenSUSE 13.1 and 13.2.