Oracle · Mysql Server · CVE-2015-3152
**Name of the Vulnerable Software and Affected Versions**
Oracle MySQL versions prior to 5.7.3
Oracle MySQL Connector/C (aka libmysqlclient) versions prior to 6.1.3
MariaDB versions prior to 5.5.44
**Description**
The issue allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack. This is due to the --ssl option being used to mean that SSL is optional.
**Recommendations**
For Oracle MySQL versions prior to 5.7.3, update to version 5.7.3 or later to resolve the issue.
For Oracle MySQL Connector/C (aka libmysqlclient) versions prior to 6.1.3, update to version 6.1.3 or later to resolve the issue.
For MariaDB versions prior to 5.5.44, update to version 5.5.44 or later to resolve the issue.