CVE-2015-3903
published 2015-05-26CVE-2015-3903: libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.60%
73.2th percentile
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.4.6.1-1 (bookworm) | phpmyadmin 4:4.4.6.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qwv-267r-c7fq: libraries/Config
ghsa_unreviewed·2022-05-14
CVE-2015-3903 [MEDIUM] GHSA-9qwv-267r-c7fq: libraries/Config
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
OSV
CVE-2015-3903: libraries/Config
osv·2015-05-26·CVSS 4.3
CVE-2015-3903 [MEDIUM] CVE-2015-3903: libraries/Config
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Debian
CVE-2015-3903: phpmyadmin - libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4....
vendor_debian·2015·CVSS 4.3
CVE-2015-3903 [MEDIUM] CVE-2015-3903: phpmyadmin - libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4....
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 4:4.4.6.1-1)
bullseye: resolved (fixed in 4:4.4.6.1-1)
forky: resolved (fixed in 4:4.4.6.1-1)
sid: resolved (fixed in 4:4.4.6.1-1)
trixie: resolved (fixed in 4:4.4.6.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-7]
bugzilla·2015-05-18·CVSS 4.3
CVE-2015-3903 [MEDIUM] CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-7]
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for
Bugzilla
CVE-2015-3903 phpMyAdmin4: phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-5]
bugzilla·2015-05-18·CVSS 4.3
CVE-2015-3903 [MEDIUM] CVE-2015-3903 phpMyAdmin4: phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-5]
CVE-2015-3903 phpMyAdmin4: phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 trac
Bugzilla
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub
bugzilla·2015-05-14·CVSS 4.3
CVE-2015-3903 [MEDIUM] CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub
A vulnerability in the API call to GitHub can be exploited to perform a
man-in-the-middle attack. Versions 4.0.x (prior to 4.0.10.10), 4.2.x (prior
to 4.2.13.3), 4.3.x (prior to 4.3.13.1) and 4.4.x (prior to 4.4.6.1) are
affected.
Discussion:
phpMyAdmin-4.4.6.1-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
phpMyAdmin-4.4.6.1-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
External References:
http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.php
---
Created phpMyAdmin tracking bugs for this issue:
Affects: e
http://cxsecurity.com/issue/WLB-2015050095http://lists.opensuse.org/opensuse-updates/2015-07/msg00008.htmlhttp://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.htmlhttp://www.debian.org/security/2015/dsa-3382http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.phphttp://www.securityfocus.com/archive/1/535547/100/0/threadedhttp://www.securityfocus.com/bid/74660http://www.securitytracker.com/id/1032403https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4http://cxsecurity.com/issue/WLB-2015050095http://lists.opensuse.org/opensuse-updates/2015-07/msg00008.htmlhttp://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.htmlhttp://www.debian.org/security/2015/dsa-3382http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.phphttp://www.securityfocus.com/archive/1/535547/100/0/threadedhttp://www.securityfocus.com/bid/74660http://www.securitytracker.com/id/1032403https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4
2015-05-26
Published