CVE-2016-6630: Input Validation
An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6630?
CVE-2016-6630 is classified as a denial-of-service (DoS) vulnerability.
How do I fix CVE-2016-6630?
To mitigate CVE-2016-6630, update phpMyAdmin to version 4.6.4 or later, 4.4.15.8 or later, or 4.0.10.17 or later.
Which versions are affected by CVE-2016-6630?
CVE-2016-6630 affects all versions of phpMyAdmin prior to 4.6.4, 4.4.15.8, and 4.0.10.17.
Can an attacker exploit CVE-2016-6630 remotely?
CVE-2016-6630 requires authenticated access, so an attacker must be a registered user to exploit it.
What impact does CVE-2016-6630 have on phpMyAdmin?
CVE-2016-6630 allows attackers to trigger a denial-of-service by submitting overly long passwords during the password change process.