Name | CVE-2016-6627 |
Description | An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1821-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
phpmyadmin (PTS) | jessie, jessie (lts) | 4:4.2.12-2+deb8u12 | fixed |
stretch (security) | 4:4.6.6-4+deb9u2 | fixed | |
stretch (lts), stretch | 4:4.6.6-4+deb9u3 | fixed | |
bullseye | 4:5.0.4+dfsg2-2+deb11u1 | fixed | |
bookworm | 4:5.2.1+dfsg-1 | fixed | |
sid, trixie | 4:5.2.1+dfsg-4 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
phpmyadmin | source | jessie | 4:4.2.12-2+deb8u6 | DLA-1821-1 | ||
phpmyadmin | source | (unstable) | 4:4.6.4+dfsg1-1 |
[wheezy] - phpmyadmin <no-dsa> (Not critical enough)
https://www.phpmyadmin.net/security/PMASA-2016-50/