CVE-2016-2042

Published on: 02/19/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:15 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Certain versions of Fedora from Fedoraproject contain the following vulnerability:

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.

  • CVE-2016-2042 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW NONE NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
openSUSE-SU-2016:0357-1: moderate: Security update for phpMyAdmin Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0357
[SECURITY] Fedora 23 Update: phpMyAdmin-4.5.4.1-1.fc23 Third Party Advisory
lists.fedoraproject.org
text/html
URL Logo FEDORA FEDORA-2016-e55278763e
openSUSE-SU-2016:0378-1: moderate: Security update to phpMyAdmin 4.4.15. Third Party Advisory
lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0378
[SECURITY] Fedora 22 Update: phpMyAdmin-4.5.4-1.fc22 Third Party Advisory
lists.fedoraproject.org
text/html
URL Logo FEDORA FEDORA-2016-e1fe01e96e
phpMyAdmin - Security - PMASA-2016-6 Patch
Vendor Advisory
www.phpmyadmin.net
text/html
URL Logo CONFIRM www.phpmyadmin.net/home_page/security/PMASA-2016-6.php
Avoid execution outside phpMyAdmin · phpmyadmin/[email protected] · GitHub Patch
github.com
text/html
URL Logo CONFIRM github.com/phpmyadmin/phpmyadmin/commit/5a3de108f26e4b0dddadddbe8ccdb1dd5526771f

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
FedoraprojectFedora22AllAllAll
Operating
System
FedoraprojectFedora23AllAllAll
Operating
System
FedoraprojectFedora22AllAllAll
Operating
System
FedoraprojectFedora23AllAllAll
Operating
System
OpensuseLeap42.1AllAllAll
Operating
System
OpensuseLeap42.1AllAllAll
Operating
System
OpensuseOpensuse13.1AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
Operating
System
OpensuseOpensuse13.1AllAllAll
Operating
System
OpensuseOpensuse13.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.1.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.10AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.11AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.12AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.13AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.13.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.14.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.3AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.3AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.4AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.5AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.6AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.6.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.7AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.8AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.9AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.3AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.1.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.10AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.11AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.12AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.13AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.13.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.14.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.15.3AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.3AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.4AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.5AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.6AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.6.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.7AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.8AllAllAll
ApplicationPhpmyadminPhpmyadmin4.4.9AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.0.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.1AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.2AllAllAll
ApplicationPhpmyadminPhpmyadmin4.5.3AllAllAll
  • cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*:
  • cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*:
  • cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*:
  • cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.13.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.14.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.6.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.13.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.14.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.15.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.6.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.4.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:phpmyadmin:phpmyadmin:4.5.3:*:*:*:*:*:*:*: