PT-2017-6471 · Percona+1 · Percona-Toolkit+2
David Busby
·
Publicado
2017-09-28
·
Atualizado
2024-06-15
·
CVE-2015-1027
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
percona-toolkit versions prior to 2.2.13
xtrabackup versions prior to 2.2.9
Description
The issue allows for silent HTTP downgrade attacks and Man In The Middle attacks. In these attacks, the server response can be modified, enabling the attacker to respond with a modified command payload. This can lead to the client returning additional running configuration information, resulting in an information disclosure of the running configuration of MySQL.
Recommendations
For percona-toolkit versions prior to 2.2.13, update to version 2.2.13 or later.
For xtrabackup versions prior to 2.2.9, update to version 2.2.9 or later.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mysql Server
Percona-Toolkit
Xtrabackup