CVE-2016-2562
published 2016-03-01CVE-2016-2562: The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers…
PriorityP430medium6.8CVSS 3.0
AVNACHPRNUINSCCNIHAN
EPSS
0.77%
51.6th percentile
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.5.5.1-1 (bookworm) | phpmyadmin 4:4.5.5.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.5.5.1-1 | 4:4.5.5.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.5.5.1-1 | 4:4.5.5.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.5.5.1-1 | 4:4.5.5.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.5.5.1-1 | 4:4.5.5.1-1 |
| phpmyadmin | phpmyadmin | >= 4.5 < 4.5.5.1 | 4.5.5.1 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
phpMyAdmin Improper Input Validation
osv·2022-05-17
CVE-2016-2562 [MEDIUM] phpMyAdmin Improper Input Validation
phpMyAdmin Improper Input Validation
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
GHSA
phpMyAdmin Improper Input Validation
ghsa·2022-05-17
CVE-2016-2562 [MEDIUM] CWE-20 phpMyAdmin Improper Input Validation
phpMyAdmin Improper Input Validation
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
OSV
CVE-2016-2562: The checkHTTP function in libraries/Config
osv·2016-03-01·CVSS 6.8
CVE-2016-2562 [MEDIUM] CVE-2016-2562: The checkHTTP function in libraries/Config
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
Debian
CVE-2016-2562: phpmyadmin - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before ...
vendor_debian·2016·CVSS 6.8
CVE-2016-2562 [MEDIUM] CVE-2016-2562: phpmyadmin - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before ...
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 4:4.5.5.1-1)
bullseye: resolved (fixed in 4:4.5.5.1-1)
forky: resolved (fixed in 4:4.5.5.1-1)
sid: resolved (fixed in 4:4.5.5.1-1)
trixie: resolved (fixed in 4:4.5.5.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [epel-all]
bugzilla·2016-03-02·CVSS 5.4
CVE-2016-2559 [MEDIUM] CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [epel-all]
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora E
Bugzilla
CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)
bugzilla·2016-03-02·CVSS 6.8
CVE-2016-2562 [MEDIUM] CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)
CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)
A vulnerability in the API call to GitHub can be exploited to perform a man-in-the-middle attack.
Affected Versions:
Versions 4.5.x (prior to 4.5.5.1) are affected.
Fixed in phpMyAdmin 4.5.5.1.
Upstream patch:
https://github.com/phpmyadmin/phpmyadmin/commit/e42b7e3aedd29dd0f7a48575f20bfc5aca0ff976
External References:
https://www.phpmyadmin.net/security/PMASA-2016-13/
Discussion:
Created phpMyAdmin tracking bugs for this issue:
Affects: fedora-all [bug 1313698]
Affects: epel-all [bug 1313699]
---
Created phpMyAdmin4 tracking bugs for this issue:
Affects: epel-5 [bug 1313700]
---
phpMyAdmin-4.0.10.15-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist,
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin4: various flaws [epel-5]
bugzilla·2016-03-02·CVSS 5.4
CVE-2016-2559 [MEDIUM] CVE-2016-2559 CVE-2016-2562 phpmyadmin4: various flaws [epel-5]
CVE-2016-2559 CVE-2016-2562 phpmyadmin4: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion:
U
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [fedora-all]
bugzilla·2016-03-02·CVSS 5.4
CVE-2016-2559 [MEDIUM] CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [fedora-all]
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178562.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178869.htmlhttps://github.com/phpmyadmin/phpmyadmin/commit/e42b7e3aedd29dd0f7a48575f20bfc5aca0ff976https://www.phpmyadmin.net/security/PMASA-2016-13/http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178562.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178869.htmlhttps://github.com/phpmyadmin/phpmyadmin/commit/e42b7e3aedd29dd0f7a48575f20bfc5aca0ff976https://www.phpmyadmin.net/security/PMASA-2016-13/
2016-03-01
Published