Candidate: CVE-2016-6617 PublicDate: 2016-12-11 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6617 http://www.phpmyadmin.net/security/PMASA-2016-40/ Description: An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected. Ubuntu-Description: Notes: ratliff> upstream says 4.6 only Bugs: Priority: medium Discovered-by: Emanuel Bronshtein Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/ceeef53 upstream_phpmyadmin: released (4:4.6.4+dfsg1-1) precise_phpmyadmin: not-affected trusty_phpmyadmin: not-affected trusty/esm_phpmyadmin: not-affected vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE xenial_phpmyadmin: not-affected devel_phpmyadmin: released (4:4.6.4+dfsg1-1)