|Description||The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 220.127.116.11 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||high (attack range: remote)|
Vulnerable and fixed packages
The table below lists information on source packages.
|jessie (security), jessie||4:4.2.12-2+deb8u2||fixed|
|buster, sid, stretch||4:4.6.6-4||fixed|
The information below is based on the following data on fixed versions.
[sarge] - phpmyadmin <not-affected> (Vulnerable code not present)