CVE-2015-3152
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade…
Does this matter?
Lower severity and a low EPSS score (7.08%). Track it; it rarely justifies an emergency change on its own.
Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 7.08% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- oracle/mysql · oracle/mysql connector\/c · mariadb/mariadb · fedoraproject/fedora · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · php/php
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlMailing List, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/Exploit, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/Third Party Advisory
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1646.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.ocert.org/advisories/ocert-2015-003.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/535397/100/1100/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74398Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032216Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2015-3152Third Party Advisory
- https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390Patch, Third Party Advisory
- https://jira.mariadb.org/browse/MDEV-7937Issue Tracking, Vendor Advisory
- https://www.duosecurity.com/blog/backronym-mysql-vulnerabilityThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlMailing List, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/Exploit, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/Third Party Advisory
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1646.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.ocert.org/advisories/ocert-2015-003.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/535397/100/1100/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74398Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032216Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.