In association with heise online

10 February 2011, 11:39

phpMyAdmin updates close security vulnerability

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

PhpMyAdmin Logo The phpMyAdmin developers have announced the release of version 3.3.9.1 and 2.11.11.2 of their database administration tool, security updates that fix a path disclosure vulnerability. According to the developers, when the README, ChangeLog or LICENSE files are removed from their original location, the scripts used to display these files can show their full path, possibly leading to further attacks.

All versions previous to 3.3.9.1 and 2.11.11.2 are said to be affected. While the developers consider the vulnerability to be non-critical, they still advise all users to upgrade as soon as possible. Alternatively, users can apply the provided patches.

Version 3.3.9.1 and 2.11.11.2 of phpMyAdmin is available to download from the project's site. Hosted on SourceForge, phpMyAdmin is made available under version 2 of the GNU General Public License (GPLv2).

See also:

(crve)

Print Version | Send by email | Permalink: http://h-online.com/-1186821
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit