SB2014072219 - Permissions, Privileges, and Access Controls in phpmyadmin (Alpine package)
Published: July 22, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-4987)
The vulnerability allows a remote #AU# to gain access to sensitive information.
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
Remediation
Install update from vendor's website.