CVE-2016-9865: Critical severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMAsafeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9865?
CVE-2016-9865 has a moderate severity level, allowing attackers to potentially exploit the vulnerability to bypass protections.
How do I fix CVE-2016-9865?
To fix CVE-2016-9865, upgrade phpMyAdmin to version 4.6.5 or later for the 4.6.x series, 4.4.15.9 or later for the 4.4.x series, or 4.0.10.18 or later for the 4.0.x series.
Which versions of phpMyAdmin are affected by CVE-2016-9865?
CVE-2016-9865 affects phpMyAdmin versions 4.6.x prior to 4.6.5, 4.4.x prior to 4.4.15.9, and 4.0.x prior to 4.0.10.18.
What causes the CVE-2016-9865 vulnerability?
The CVE-2016-9865 vulnerability is caused by a bug in serialized string parsing that allows for bypassing the PMA_safeUnserialize() function.
Who should be concerned about CVE-2016-9865?
Users and administrators of phpMyAdmin running affected versions should be concerned about CVE-2016-9865 due to its potential for exploitation.