UBUNTU-CVE-2016-9866

Source
https://ubuntu.com/security/CVE-2016-9866
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-9866.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2016-9866
Related
Published
2016-12-11T03:00:00Z
Modified
2016-12-11T03:00:00Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

References

Affected packages

Ubuntu:Pro:14.04:LTS / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/ubuntu/phpmyadmin?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.0.10-1ubuntu0.1+esm3

Affected versions

4:4.*

4:4.0.6-1
4:4.0.8-1
4:4.0.9-1
4:4.0.10-1
4:4.0.10-1ubuntu0.1
4:4.0.10-1ubuntu0.1+esm1
4:4.0.10-1ubuntu0.1+esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4:4.0.10-1ubuntu0.1+esm3",
            "binary_name": "phpmyadmin"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/ubuntu/phpmyadmin?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.5.4.1-2ubuntu2.1+esm5

Affected versions

4:4.*

4:4.4.13.1-1
4:4.5.0.2-2
4:4.5.1-1
4:4.5.1-2
4:4.5.1-3
4:4.5.2-1
4:4.5.2-2
4:4.5.3.1-1
4:4.5.4-1
4:4.5.4.1-2
4:4.5.4.1-2ubuntu1
4:4.5.4.1-2ubuntu2
4:4.5.4.1-2ubuntu2.1
4:4.5.4.1-2ubuntu2.1+esm2
4:4.5.4.1-2ubuntu2.1+esm3
4:4.5.4.1-2ubuntu2.1+esm4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4:4.5.4.1-2ubuntu2.1+esm5",
            "binary_name": "phpmyadmin"
        }
    ]
}