PT-2015-1694 · Mysql Server+6 · Mysql Server+7

Adam Langley

+1

·

Publicado

2015-07-09

·

Atualizado

2024-06-15

·

CVE-2015-1793

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1n through 1.0.1o OpenSSL versions 1.0.2b through 1.0.2c MySQL Server version 5.6.25 and earlier
Description The issue is related to the processing of X.509 Basic Constraints cA values during the identification of alternative certificate chains, which can allow remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate. This can enable an attacker to forge "trusted" certificates that could be used to conduct man-in-the-middle attacks. The vulnerability affects applications that verify certificates, including SSL/Transport Layer Security (TLS)/Datagram Transport Layer Security (DTLS) clients and SSL/TLS/DTLS servers using client authentication.
Recommendations For OpenSSL versions 1.0.1n through 1.0.1o, update to a version that addresses this vulnerability. For OpenSSL versions 1.0.2b through 1.0.2c, update to a version that addresses this vulnerability. For MySQL Server version 5.6.25 and earlier, update to a version that addresses this vulnerability. As a temporary workaround, consider restricting access to untrusted certificates to minimize the risk of exploitation. Avoid using the vulnerable X509 verify cert function until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1600
BDU:2015-11040
CVE-2015-1793
HPSBUX03388
MGASA-2015-0274
OPENSUSE-SU-2015_2243-1
OPENSUSE-SU-2024:10200-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
SUSE-SU-2015:2303-1

Produtos afetados

Alt Linux
Cisco Ios Xe
Cisco Wls
Hp-Ux
Junos
Mysql Server
Openssl
Suse