CVE-2016-6632
MEDIUM5.9EPSS 0.57%phpMyAdmin Denial of service (DOS) attack with dbase extension
Published: 5/17/2022Modified: 5/7/2026
Description
An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected packages (3)
- Alpine/phpmyadminfrom 0, < 4.4.15.8-r0
- Debian/phpmyadminfrom 0, < 4:4.6.4+dfsg1-1
- Packagist/phpmyadmin/phpmyadmin>= 4.6, < 4.6.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-6632
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2016-6632
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2016-6632
- PATCHhttps://github.com/phpmyadmin/composer
- WEBhttps://lists.debian.org/debian-lts-announce/2019/06/msg00009.html
- WEBhttps://security.gentoo.org/glsa/201701-32
- WEBhttps://www.phpmyadmin.net/security/PMASA-2016-55
- WEBhttp://www.securityfocus.com/bid/92497