CVE-2016-6623: Input Validation
An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What versions are affected by CVE-2016-6623?
CVE-2016-6623 affects phpMyAdmin versions 4.6.x prior to 4.6.4, 4.4.x prior to 4.4.15.8, and 4.0.x prior to 4.0.10.17.
What is the nature of the vulnerability in CVE-2016-6623?
CVE-2016-6623 is a denial-of-service (DoS) vulnerability that allows an authorized user to disrupt the server by exploiting a loop with large input values.
How can I mitigate the effects of CVE-2016-6623?
To mitigate CVE-2016-6623, upgrade affected phpMyAdmin versions to 4.6.4, 4.4.15.8, or 4.0.10.17 or later.
What should I do if I am running a vulnerable version due to CVE-2016-6623?
If running a vulnerable version, you should immediately update phpMyAdmin to a fixed version to prevent possible exploitation.
Is CVE-2016-6623 a critical vulnerability?
CVE-2016-6623 is classified as a denial-of-service vulnerability, which can significantly disrupt server availability.