CVE-2016-9852: Infoleak
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9852?
CVE-2016-9852 has a medium severity rating, potentially exposing sensitive directory information.
How do I fix CVE-2016-9852?
To fix CVE-2016-9852, upgrade phpMyAdmin to a version later than 4.6.4 where the vulnerability has been addressed.
What versions of phpMyAdmin are affected by CVE-2016-9852?
CVE-2016-9852 affects phpMyAdmin versions from 4.4.0 to 4.6.4.
What kind of information can be exposed due to CVE-2016-9852?
CVE-2016-9852 can cause phpMyAdmin to reveal the full path of the directory where it is installed.
Is there a method to mitigate CVE-2016-9852 without updating?
Without updating, mitigate CVE-2016-9852 by restricting access to phpMyAdmin endpoints through network security rules.