[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 30 Mar 2008 15:20:48 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com,
"Steven M. Christey" <coley@...us.mitre.org>
Subject: CVE request: phpmyadmin (PMASA-2008-2)
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2
Announcement-ID: PMASA-2008-2
Date: 2008-03-29
Summary:
Credentials disclosure on shared hosts via session data
Description:
We received an advisory from Jim Hermann, and we wish to thank him for his
work. phpMyAdmin saves sensitive information like the MySQL username and
password and the Blowfish secret key in session data, which might be
unprotected on a shared host.
--
Hanno Böck Blog: http://www.hboeck.de/
GPG: 3DBD3B20 Jabber/Mail: hanno@...eck.de
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ