Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.
Monthly Archives: March 2016
CVE-2016-2560
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.
CVE-2016-2561
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.
CVE-2016-2562
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
RHBA-2016:0316-1: ovirt-node bug fix and enhancement update for RHEV 3.5.8
Red Hat Enterprise Linux: Updated ovirt-node packages that fix several bugs and add various enhancements
are now available.
RHBA-2016:0315-1: Red Hat Enterprise Virtualization Manager 3.5.8 update
Red Hat Enterprise Linux: Red Hat Enterprise Virtualization Manager 3.5.8 is now available.
RHSA-2016:0329-1: Moderate: openstack-swift security update
Red Hat Enterprise Linux: Updated openstack-swift packages that fix two security issues are now
available for Red Hat Gluster Storage 3.1 update 2 in Red Hat Enterprise
Linux 6.
Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2016-0737, CVE-2016-0738
RHSA-2016:0328-1: Moderate: openstack-swift security update
Red Hat Enterprise Linux: Updated openstack-swift packages that fix two security issues are now
available for Red Hat Gluster Storage 3.1 update 2 in Red Hat Enterprise
Linux 7.
Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2016-0737, CVE-2016-0738
RHBA-2016:0326-1: gluster-smb bug fix and enhancement update
Red Hat Enterprise Linux: Updated Samba package that fixes one bug and adds one enhancement is now
available for Red Hat Gluster Storage 3.1 update 2
RHBA-2016:0322-1: Red Hat Gluster Storage 3.1 update 2
Red Hat Enterprise Linux: Updated glusterfs packages that fix several bugs and add various
enhancements are now available for the Red Hat Common channel of Red Hat
Enterprise Linux 5.