CVE Vulnerabilities

CVE-2016-1927

Published: Feb 20, 2016 | Modified: Nov 28, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 4.0.0 (including) 4.0.0 (including)
Phpmyadmin Phpmyadmin 4.0.0-rc2 (including) 4.0.0-rc2 (including)
Phpmyadmin Phpmyadmin 4.0.0-rc3 (including) 4.0.0-rc3 (including)
Phpmyadmin Phpmyadmin 4.0.1 (including) 4.0.1 (including)
Phpmyadmin Phpmyadmin 4.0.10 (including) 4.0.10 (including)
Phpmyadmin Phpmyadmin 4.0.10.1 (including) 4.0.10.1 (including)
Phpmyadmin Phpmyadmin 4.0.10.2 (including) 4.0.10.2 (including)
Phpmyadmin Phpmyadmin 4.0.10.3 (including) 4.0.10.3 (including)
Phpmyadmin Phpmyadmin 4.0.10.4 (including) 4.0.10.4 (including)
Phpmyadmin Phpmyadmin 4.0.10.5 (including) 4.0.10.5 (including)
Phpmyadmin Phpmyadmin 4.0.10.6 (including) 4.0.10.6 (including)
Phpmyadmin Phpmyadmin 4.0.10.7 (including) 4.0.10.7 (including)
Phpmyadmin Phpmyadmin 4.0.10.8 (including) 4.0.10.8 (including)
Phpmyadmin Phpmyadmin 4.0.10.9 (including) 4.0.10.9 (including)
Phpmyadmin Phpmyadmin 4.0.10.10 (including) 4.0.10.10 (including)
Phpmyadmin Phpmyadmin 4.0.10.11 (including) 4.0.10.11 (including)
Phpmyadmin Phpmyadmin 4.0.10.12 (including) 4.0.10.12 (including)
Phpmyadmin Phpmyadmin 4.4.0 (including) 4.4.0 (including)
Phpmyadmin Phpmyadmin 4.4.1 (including) 4.4.1 (including)
Phpmyadmin Phpmyadmin 4.4.1.1 (including) 4.4.1.1 (including)
Phpmyadmin Phpmyadmin 4.4.2 (including) 4.4.2 (including)
Phpmyadmin Phpmyadmin 4.4.3 (including) 4.4.3 (including)
Phpmyadmin Phpmyadmin 4.4.4 (including) 4.4.4 (including)
Phpmyadmin Phpmyadmin 4.4.5 (including) 4.4.5 (including)
Phpmyadmin Phpmyadmin 4.4.6 (including) 4.4.6 (including)
Phpmyadmin Phpmyadmin 4.4.6.1 (including) 4.4.6.1 (including)
Phpmyadmin Phpmyadmin 4.4.7 (including) 4.4.7 (including)
Phpmyadmin Phpmyadmin 4.4.8 (including) 4.4.8 (including)
Phpmyadmin Phpmyadmin 4.4.9 (including) 4.4.9 (including)
Phpmyadmin Phpmyadmin 4.4.10 (including) 4.4.10 (including)
Phpmyadmin Phpmyadmin 4.4.11 (including) 4.4.11 (including)
Phpmyadmin Phpmyadmin 4.4.12 (including) 4.4.12 (including)
Phpmyadmin Phpmyadmin 4.4.13 (including) 4.4.13 (including)
Phpmyadmin Phpmyadmin 4.4.13.1 (including) 4.4.13.1 (including)
Phpmyadmin Phpmyadmin 4.4.14.1 (including) 4.4.14.1 (including)
Phpmyadmin Phpmyadmin 4.4.15 (including) 4.4.15 (including)
Phpmyadmin Phpmyadmin 4.4.15.1 (including) 4.4.15.1 (including)
Phpmyadmin Phpmyadmin 4.4.15.2 (including) 4.4.15.2 (including)
Phpmyadmin Phpmyadmin 4.4.15.3 (including) 4.4.15.3 (including)
Phpmyadmin Phpmyadmin 4.5.0 (including) 4.5.0 (including)
Phpmyadmin Phpmyadmin 4.5.0.1 (including) 4.5.0.1 (including)
Phpmyadmin Phpmyadmin 4.5.0.2 (including) 4.5.0.2 (including)
Phpmyadmin Phpmyadmin 4.5.1 (including) 4.5.1 (including)
Phpmyadmin Phpmyadmin 4.5.2 (including) 4.5.2 (including)
Phpmyadmin Phpmyadmin 4.5.3 (including) 4.5.3 (including)
Phpmyadmin Ubuntu esm-infra-legacy/trusty *
Phpmyadmin Ubuntu precise *
Phpmyadmin Ubuntu trusty *
Phpmyadmin Ubuntu trusty/esm *
Phpmyadmin Ubuntu upstream *
Phpmyadmin Ubuntu vivid *
Phpmyadmin Ubuntu wily *

References