Candidate: CVE-2016-6631 PublicDate: 2016-12-11 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6631 http://www.phpmyadmin.net/security/PMASA-2016-54/ Description: An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. Ubuntu-Description: It was discovered that phpmyadmin incorrectly handled request query strings. An attacker could possibly use this to execute arbitrary code. Notes: Bugs: Priority: high Discovered-by: Emanuel Bronshtein Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/0a3c6d3 upstream_phpmyadmin: released (4:4.6.4+dfsg1-1) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needed) trusty_phpmyadmin: released (4:4.0.10-1ubuntu0.1) trusty/esm_phpmyadmin: released (4:4.0.10-1ubuntu0.1) vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE xenial_phpmyadmin: released (4:4.5.4.1-2ubuntu2.1) yakkety_phpmyadmin: not-affected (4:4.6.4+dfsg1-1) zesty_phpmyadmin: not-affected (4:4.6.4+dfsg1-1) artful_phpmyadmin: not-affected (4:4.6.4+dfsg1-1) bionic_phpmyadmin: not-affected (4:4.6.4+dfsg1-1) devel_phpmyadmin: not-affected (4:4.6.4+dfsg1-1)