CVE-2016-6629: Critical severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Other sources
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6629?
CVE-2016-6629 has a medium severity level due to potential unauthorized access facilitated by cookie value reuse.
How do I fix CVE-2016-6629?
To fix CVE-2016-6629, upgrade to phpMyAdmin versions 4.0.10.17, 4.4.15.8, or 4.6.4 or later.
Which versions are affected by CVE-2016-6629?
CVE-2016-6629 affects phpMyAdmin versions prior to 4.6.4, 4.4.15.8, and 4.0.10.17.
What type of attack does CVE-2016-6629 enable?
CVE-2016-6629 enables an attacker to bypass server restrictions by reusing certain cookie values.
Is upgrading phpMyAdmin the only solution for CVE-2016-6629?
Yes, upgrading to the specified versions is the recommended and effective solution to mitigate CVE-2016-6629.