Bug 1157614 - (CVE-2019-18622) VUL-0: CVE-2019-18622: phpMyAdmin: SQL injection in Designer feature (PMASA-2019-5)
(CVE-2019-18622)
VUL-0: CVE-2019-18622: phpMyAdmin: SQL injection in Designer feature (PMASA-2...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-11-23 09:46 UTC by Andreas Stieger
Modified: 2020-01-19 15:38 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2019-11-23 09:46:50 UTC
A vulnerability was reported in phpMyAdmin where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

This is similar to PMASA-2019-2 and PMASA-2019-3, but has affected different versions. CVE-2019-18622 CWE-661 PMASA-2019-5

phpMyAdmin versions prior to 4.9.2 are affected, at least as old as 4.7.7.

References:
https://www.phpmyadmin.net/security/PMASA-2019-5/
https://github.com/phpmyadmin/phpmyadmin/commit/ff541af95d7155d8dd326f331b5e248fea8e7111
Comment 1 Swamp Workflow Management 2019-11-23 10:30:06 UTC
This is an autogenerated message for OBS integration:
This bug (1157614) was mentioned in
https://build.opensuse.org/request/show/750416 15.0+15.1+Backports:SLE-12+Backports:SLE-15+Backports:SLE-15-SP1 / phpMyAdmin
Comment 2 Andreas Stieger 2019-11-23 11:28:20 UTC
For TW: https://build.opensuse.org/request/show/750415
Comment 3 Swamp Workflow Management 2019-12-01 14:11:06 UTC
openSUSE-SU-2019:2599-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1157614
CVE References: CVE-2019-18622
Sources used:
openSUSE Leap 15.1 (src):    phpMyAdmin-4.9.2-lp151.2.9.1
openSUSE Leap 15.0 (src):    phpMyAdmin-4.9.2-lp150.37.1
openSUSE Backports SLE-15-SP1 (src):    phpMyAdmin-4.9.2-bp151.3.9.1
openSUSE Backports SLE-15 (src):    phpMyAdmin-4.9.2-bp150.37.1
Comment 4 Swamp Workflow Management 2019-12-01 14:11:49 UTC
openSUSE-SU-2019:2599-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1157614
CVE References: CVE-2019-18622
Sources used:
openSUSE Leap 15.1 (src):    phpMyAdmin-4.9.2-lp151.2.9.1
openSUSE Leap 15.0 (src):    phpMyAdmin-4.9.2-lp150.37.1
openSUSE Backports SLE-15-SP1 (src):    phpMyAdmin-4.9.2-bp151.3.9.1
openSUSE Backports SLE-15 (src):    phpMyAdmin-4.9.2-bp150.37.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    phpMyAdmin-4.9.2-37.1
Comment 5 Andreas Stieger 2019-12-01 19:00:08 UTC
released
Comment 6 Swamp Workflow Management 2020-01-14 20:17:11 UTC
openSUSE-SU-2020:0056-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1150914,1157614,1160456
CVE References: CVE-2019-12922,CVE-2019-18622,CVE-2020-5504
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    phpMyAdmin-4.9.4-40.1