Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Sun, 30 Mar 2008 15:20:48 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com,
  "Steven M. Christey" <coley@...us.mitre.org>
Subject: CVE request: phpmyadmin (PMASA-2008-2)

http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2

Announcement-ID: PMASA-2008-2
Date: 2008-03-29

Summary:
Credentials disclosure on shared hosts via session data

Description:
We received an advisory from Jim Hermann, and we wish to thank him for his 
work. phpMyAdmin saves sensitive information like the MySQL username and 
password and the Blowfish secret key in session data, which might be 
unprotected on a shared host. 

-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux