---
title: "CVE-2016-6606\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-6606?format=md
keywords: index, follow
---

# CVE-2016-6606

Publication date 11 December 2016

Last updated 25 August 2025

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2016-6606?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in cookie encryption in phpMyAdmin. The decryption
of the username/password is vulnerable to a padding oracle attack. This can
allow an attacker who has access to a user's browser cookie file to decrypt
the username and password. Furthermore, the same initialization vector (IV)
is used to hash the username and password stored in the phpMyAdmin cookie.
If a user has the same password as their username, an attacker who examines
the browser cookie can see that they are the same - but the attacker can
not directly decode these values from the cookie as it is still hashed. All
4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and
4.0.x versions (prior to 4.0.10.17) are affected.

### From the Ubuntu Security Team

It was discovered that phpmyadmin incorrectly handled cookie encryption.
An attacker with access to cookies could possibly use this to determine
information about user credentials.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| phpmyadmin | 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Fixed 4:4.5.4.1-2ubuntu2.1 |
| 14.04 LTS trusty | Fixed 4:4.0.10-1ubuntu0.1 |
| 12.04 LTS precise | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2016-6606?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| phpmyadmin | * Upstream:   [cd682a6](https://github.com/phpmyadmin/phpmyadmin/commit/cd682a6) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6606)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-6606)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-6606)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-6606)

### Other references

* <http://www.phpmyadmin.net/security/PMASA-2016-29/>
* <https://www.cve.org/CVERecord?id=CVE-2016-6606>
