Oval Definition:oval:com.ubuntu.precise:def:20112507000
Revision Date:2011-07-14Version:1
Title:CVE-2011-2507 on Ubuntu 12.04 LTS (precise) - medium.
Description:libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2011-2507
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'phpmyadmin' package in precise was vulnerable but has been fixed (note: '4:3.4.3.1-1').
  • BACK