CVE-2016-6606

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-6606
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6606.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-6606
Related
Published
2016-12-11T02:59:10Z
Modified
2024-09-18T02:54:19.112612Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the same password as their username, an attacker who examines the browser cookie can see that they are the same - but the attacker can not directly decode these values from the cookie as it is still hashed. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

References

Affected packages

Alpine:v3.2 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:apk/alpine/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.15.8-r0

Affected versions

3.*

3.3.10-r0
3.3.10-r1
3.3.10-r2
3.4.9-r0
3.4.11.1-r0

4.*

4.0.0-r0
4.0.1-r0
4.0.2-r0
4.0.3-r0
4.0.4.1-r0
4.0.4.2-r0
4.0.5-r0
4.0.6-r0
4.0.7-r0
4.0.8-r0
4.0.8-r1
4.0.8-r2
4.0.9-r0
4.0.10-r0
4.1.4-r0
4.1.5-r0
4.1.6-r0
4.1.7-r0
4.1.8-r0
4.1.9-r0
4.1.11-r0
4.1.12-r0
4.1.13-r0
4.1.14-r0
4.2.0-r0
4.2.1-r0
4.2.2-r0
4.2.3-r0
4.2.4-r0
4.2.5-r0
4.2.6-r0
4.2.7-r0
4.2.7.1-r0
4.2.8-r0
4.2.8.1-r0
4.2.9-r0
4.2.9.1-r0
4.2.10-r0
4.2.10.1-r0
4.2.11-r0
4.2.12-r0
4.2.13.1-r0
4.3.0-r0
4.3.1-r0
4.3.3-r0
4.3.4-r0
4.3.5-r0
4.3.7-r0
4.3.8-r0
4.3.9-r0
4.3.10-r0
4.3.11.1-r0
4.3.12-r0
4.3.13-r0
4.4.1.1-r0
4.4.3-r0
4.4.4-r0
4.4.5-r0
4.4.7-r0
4.4.15-r0
4.4.15.1-r0
4.4.15.4-r0
4.4.15.7-r0

Debian:11 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.6.4+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.6.4+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:4.6.4+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/phpmyadmin/phpmyadmin

Affected ranges

Type
GIT
Repo
https://github.com/phpmyadmin/phpmyadmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected

Affected versions

Other

RELEASE_2_10_0
RELEASE_2_10_0RC1
RELEASE_2_10_0_1
RELEASE_2_10_0_2
RELEASE_2_10_1RC1
RELEASE_2_10_2
RELEASE_2_10_3
RELEASE_2_10_3RC1
RELEASE_2_11_0
RELEASE_2_11_0BETA1
RELEASE_2_11_0RC1
RELEASE_2_11_0RC2
RELEASE_2_11_1
RELEASE_2_11_10
RELEASE_2_11_10_1
RELEASE_2_11_11
RELEASE_2_11_11RC1
RELEASE_2_11_11_1
RELEASE_2_11_11_2
RELEASE_2_11_11_3
RELEASE_2_11_1RC1
RELEASE_2_11_1_1
RELEASE_2_11_1_2
RELEASE_2_11_2
RELEASE_2_11_2RC1
RELEASE_2_11_2_1
RELEASE_2_11_2_2
RELEASE_2_11_3
RELEASE_2_11_3RC1
RELEASE_2_11_4
RELEASE_2_11_4RC1
RELEASE_2_11_5
RELEASE_2_11_5RC1
RELEASE_2_11_5_1
RELEASE_2_11_5_2
RELEASE_2_11_6
RELEASE_2_11_6RC1
RELEASE_2_11_7
RELEASE_2_11_7RC1
RELEASE_2_11_7RC2
RELEASE_2_11_7_1
RELEASE_2_11_8
RELEASE_2_11_8RC1
RELEASE_2_11_8_1
RELEASE_2_11_9
RELEASE_2_11_9_1
RELEASE_2_11_9_2
RELEASE_2_11_9_3
RELEASE_2_11_9_4
RELEASE_2_11_9_5
RELEASE_2_11_9_6
RELEASE_2_2_0
RELEASE_2_2_1
RELEASE_2_2_2
RELEASE_2_2_3
RELEASE_2_2_4
RELEASE_2_2_5
RELEASE_2_2_6
RELEASE_2_2_7PL1
RELEASE_2_3_0
RELEASE_2_3_1
RELEASE_2_3_2
RELEASE_2_3_3PL1
RELEASE_2_4_0
RELEASE_2_5_0
RELEASE_2_5_1
RELEASE_2_5_2
RELEASE_2_5_4
RELEASE_2_5_5PL1
RELEASE_2_5_6
RELEASE_2_5_7PL1
RELEASE_2_6_1PL3
RELEASE_2_6_2PL1
RELEASE_2_6_3PL1
RELEASE_2_6_4PL4
RELEASE_2_7_0PL2
RELEASE_2_8_0_4
RELEASE_2_8_1
RELEASE_2_8_2_4
RELEASE_2_9_0
RELEASE_2_9_0_1
RELEASE_2_9_0_2
RELEASE_2_9_1_1
RELEASE_2_9_2
RELEASE_2_9_2RC1
RELEASE_3_0_0
RELEASE_3_0_0ALPHA
RELEASE_3_0_0BETA
RELEASE_3_0_0RC1
RELEASE_3_0_0RC2
RELEASE_3_0_1
RELEASE_3_0_1RC1
RELEASE_3_0_1_1
RELEASE_3_1_0
RELEASE_3_1_0BETA1
RELEASE_3_1_0RC1
RELEASE_3_1_1
RELEASE_3_1_2
RELEASE_3_1_2RC1
RELEASE_3_1_3
RELEASE_3_1_3RC1
RELEASE_3_1_3_1
RELEASE_3_1_3_2
RELEASE_3_1_4
RELEASE_3_1_4RC1
RELEASE_3_1_4RC2
RELEASE_3_1_5
RELEASE_3_1_5RC1
RELEASE_3_2_0
RELEASE_3_2_0BETA1
RELEASE_3_2_0RC1
RELEASE_3_2_0_1
RELEASE_3_2_2
RELEASE_3_2_2RC1
RELEASE_3_2_2_1
RELEASE_3_2_3
RELEASE_3_2_3RC1
RELEASE_3_2_4
RELEASE_3_2_4RC1
RELEASE_3_2_5
RELEASE_3_2_5RC1
RELEASE_3_2_5RC2
RELEASE_3_3_0
RELEASE_3_3_0ALPHA1
RELEASE_3_3_0BETA1
RELEASE_3_3_0RC1
RELEASE_3_3_0RC2
RELEASE_3_3_0RC3
RELEASE_3_3_1
RELEASE_3_3_10
RELEASE_3_3_10RC1
RELEASE_3_3_10_1
RELEASE_3_3_10_2
RELEASE_3_3_10_3
RELEASE_3_3_10_4
RELEASE_3_3_10_5
RELEASE_3_3_1RC1
RELEASE_3_3_2
RELEASE_3_3_2RC1
RELEASE_3_3_3
RELEASE_3_3_3RC1
RELEASE_3_3_4
RELEASE_3_3_4RC1
RELEASE_3_3_5
RELEASE_3_3_5RC1
RELEASE_3_3_5_1
RELEASE_3_3_6
RELEASE_3_3_6RC1
RELEASE_3_3_7
RELEASE_3_3_7RC1
RELEASE_3_3_8
RELEASE_3_3_8RC1
RELEASE_3_3_8_1
RELEASE_3_3_9
RELEASE_3_3_9RC1
RELEASE_3_3_9_1
RELEASE_3_3_9_2
RELEASE_3_4_0
RELEASE_3_4_0ALPHA1
RELEASE_3_4_0ALPHA2
RELEASE_3_4_0BETA1
RELEASE_3_4_0BETA2
RELEASE_3_4_0BETA3
RELEASE_3_4_0BETA4
RELEASE_3_4_0RC1
RELEASE_3_4_0RC2
RELEASE_3_4_1
RELEASE_3_4_10
RELEASE_3_4_10RC1
RELEASE_3_4_10_1
RELEASE_3_4_11
RELEASE_3_4_11RC1
RELEASE_3_4_11_1
RELEASE_3_4_1RC1
RELEASE_3_4_2
RELEASE_3_4_2RC1
RELEASE_3_4_3
RELEASE_3_4_3RC1
RELEASE_3_4_3_1
RELEASE_3_4_3_2
RELEASE_3_4_4
RELEASE_3_4_4RC1
RELEASE_3_4_5
RELEASE_3_4_5RC1
RELEASE_3_4_6
RELEASE_3_4_6RC1
RELEASE_3_4_7
RELEASE_3_4_7RC1
RELEASE_3_4_7_1
RELEASE_3_4_8
RELEASE_3_4_8RC1
RELEASE_3_4_9
RELEASE_3_4_9RC1
RELEASE_3_5_0
RELEASE_3_5_0ALPHA1
RELEASE_3_5_0BETA1
RELEASE_3_5_0RC1
RELEASE_3_5_0RC2
RELEASE_3_5_1
RELEASE_3_5_1RC1
RELEASE_3_5_2
RELEASE_3_5_2RC1
RELEASE_3_5_2_1
RELEASE_3_5_2_2
RELEASE_3_5_3
RELEASE_3_5_3RC1
RELEASE_3_5_4
RELEASE_3_5_4RC1
RELEASE_3_5_5RC1
RELEASE_3_5_6
RELEASE_3_5_6RC1
RELEASE_3_5_7
RELEASE_3_5_7RC1
RELEASE_3_5_8
RELEASE_3_5_8RC1
RELEASE_3_5_8_1
RELEASE_4_0_0
RELEASE_4_0_0ALPHA1
RELEASE_4_0_0ALPHA2
RELEASE_4_0_0BETA1
RELEASE_4_0_0BETA2
RELEASE_4_0_0BETA3
RELEASE_4_0_0RC1
RELEASE_4_0_0RC2
RELEASE_4_0_0RC3
RELEASE_4_0_0RC4
RELEASE_4_0_10
RELEASE_4_0_10_1
RELEASE_4_0_10_2
RELEASE_4_0_10_3
RELEASE_4_0_10_4
RELEASE_4_0_10_5
RELEASE_4_0_10_6
RELEASE_4_0_10_7
RELEASE_4_0_1RC1
RELEASE_4_0_2
RELEASE_4_0_2RC1
RELEASE_4_0_3
RELEASE_4_0_3RC1
RELEASE_4_0_4
RELEASE_4_0_4RC1
RELEASE_4_0_4_1
RELEASE_4_0_4_2
RELEASE_4_0_5RC1
RELEASE_4_0_6
RELEASE_4_0_6RC1
RELEASE_4_0_6RC2
RELEASE_4_1_0ALPHA1
RELEASE_4_1_0ALPHA2
RELEASE_4_1_0BETA1
RELEASE_4_1_0BETA2
RELEASE_4_1_0RC1
RELEASE_4_1_0RC2
RELEASE_4_1_0RC3
RELEASE_4_2_0
RELEASE_4_2_0ALPHA1
RELEASE_4_2_0ALPHA2
RELEASE_4_2_0BETA1
RELEASE_4_2_0RC1
RELEASE_4_2_10
RELEASE_4_2_10_1
RELEASE_4_2_11
RELEASE_4_2_12
RELEASE_4_2_13
RELEASE_4_2_13_1
RELEASE_4_2_7
RELEASE_4_2_7_1
RELEASE_4_2_8
RELEASE_4_2_8_1
RELEASE_4_2_9
RELEASE_4_2_9_1
RELEASE_4_3_0
RELEASE_4_3_0ALPHA1
RELEASE_4_3_0BETA1
RELEASE_4_3_0RC1
RELEASE_4_3_0RC2
RELEASE_4_3_1
RELEASE_4_3_10
RELEASE_4_3_11
RELEASE_4_3_11_1
RELEASE_4_3_12
RELEASE_4_3_13
RELEASE_4_3_2
RELEASE_4_3_3
RELEASE_4_3_4
RELEASE_4_3_5
RELEASE_4_3_6
RELEASE_4_3_7
RELEASE_4_3_8
RELEASE_4_3_9
RELEASE_4_4_0
RELEASE_4_4_0ALPHA1
RELEASE_4_4_1
RELEASE_4_4_10
RELEASE_4_4_11
RELEASE_4_4_12
RELEASE_4_4_13
RELEASE_4_4_13_1
RELEASE_4_4_14
RELEASE_4_4_14_1
RELEASE_4_4_15
RELEASE_4_4_15_1
RELEASE_4_4_15_2
RELEASE_4_4_1_1
RELEASE_4_4_2
RELEASE_4_4_3
RELEASE_4_4_4
RELEASE_4_4_5
RELEASE_4_4_6
RELEASE_4_4_6_1
RELEASE_4_4_7
RELEASE_4_4_8
RELEASE_4_4_9
RELEASE_4_5_0
RELEASE_4_5_0RC1
RELEASE_4_5_0_1
RELEASE_4_5_0_2
RELEASE_4_5_1
RELEASE_4_5_2
RELEASE_4_5_3
RELEASE_4_5_3_1
RELEASE_4_5_4
RELEASE_4_5_4_1
RELEASE_4_5_5
RELEASE_4_5_5_1
RELEASE_4_6_0
RELEASE_4_6_0ALPHA1
RELEASE_4_6_0RC1
RELEASE_4_6_0RC2
RELEASE_4_6_1