Debian Security Advisory

DLA-1821-1 phpmyadmin -- LTS security update

Date Reported:
17 Jun 2019
Affected Packages:
phpmyadmin
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 930017.
In Mitre's CVE dictionary: CVE-2016-6606, CVE-2016-6607, CVE-2016-6611, CVE-2016-6612, CVE-2016-6613, CVE-2016-6624, CVE-2016-6626, CVE-2016-6627, CVE-2016-6628, CVE-2016-6630, CVE-2016-6631, CVE-2016-6632, CVE-2016-9849, CVE-2016-9850, CVE-2016-9861, CVE-2016-9864, CVE-2019-12616.
More information:

Multiple security vulnerabilities were fixed in phpmyadmin, a MySQL web administration tool, which prevent possible SQL injection attacks, CSRF, the bypass of user restrictions, information disclosure or denial-of-service.

For Debian 8 Jessie, these problems have been fixed in version 4:4.2.12-2+deb8u6.

We recommend that you upgrade your phpmyadmin packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS