CVE-2016-9863: Input Validation
Published Dec 11, 2016
·Updated
An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.
Affected Software
6 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.6.0<4.6.5
4.6.5
phpMyAdmin phpMyAdmin=4.6.0
phpMyAdmin phpMyAdmin=4.6.1
phpMyAdmin phpMyAdmin=4.6.2
phpMyAdmin phpMyAdmin=4.6.3
phpMyAdmin phpMyAdmin=4.6.4
Remediation
Patch Available
Event History
Dec 11, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
May 17, 2022
Advisory Published
02:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-9863?
CVE-2016-9863 has a severity rating that indicates it can lead to a Denial of Service (DoS) condition.
2
How do I fix CVE-2016-9863?
To fix CVE-2016-9863, upgrade phpMyAdmin to version 4.6.5 or later.
3
Which versions of phpMyAdmin are affected by CVE-2016-9863?
All phpMyAdmin versions from 4.6.0 to 4.6.4 are affected by CVE-2016-9863.
4
What type of vulnerability is CVE-2016-9863?
CVE-2016-9863 is a Denial of Service vulnerability related to table partitioning.
5
Can CVE-2016-9863 be exploited remotely?
Yes, CVE-2016-9863 can be exploited remotely through specially crafted requests.