Bug 776698

Summary: VUL-1: CVE-2012-4219: phpMyAdmin: full path disclosure / info leak due to missing lib
Product: [Novell Products] SUSE Security Incidents Reporter: Matthias Weckbecker <mweckbecker>
Component: IncidentsAssignee: Christian Wittmer <chris>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: meissner, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Matthias Weckbecker 2012-08-21 09:46:09 UTC
An issue in phpMyAdmin has recently been reported [1]. Attackers could obtain
the full path to phpMyAdmin.

[1] http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php
Comment 1 Christian Wittmer 2012-08-21 14:58:09 UTC
update to 3.5.2.2, ongoing work
Comment 2 Swamp Workflow Management 2012-08-21 22:00:20 UTC
bugbot adjusting priority
Comment 3 Marcus Meissner 2012-08-30 09:27:56 UTC
released
Comment 4 Swamp Workflow Management 2012-08-30 10:08:50 UTC
openSUSE-SU-2012:1062-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 776698,776701
CVE References: CVE-2012-4219,CVE-2012-4345
Sources used:
openSUSE 12.2 (src):    phpMyAdmin-3.5.2.2-1.4.1
openSUSE 12.1 (src):    phpMyAdmin-3.5.2.2-1.27.1