Input validation error in phpMyAdmin - CVE-2016-6618

 

Input validation error in phpMyAdmin - CVE-2016-6618

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33796
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6618
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.

An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)
Opensuse

How to mitigate CVE-2016-6618

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.8-r0

External References

Related Security Bulletins