PT-2015-6079 · Oracle+5 · Mysql Server+7

Adam Goodman

·

Published

2015-06-11

·

Updated

2024-06-15

·

CVE-2015-3152

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions prior to 5.7.3 Oracle MySQL Connector/C (aka libmysqlclient) versions prior to 6.1.3 MariaDB versions prior to 5.5.44
Description The issue allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack. This is due to the --ssl option being used to mean that SSL is optional.
Recommendations For Oracle MySQL versions prior to 5.7.3, update to version 5.7.3 or later to resolve the issue. For Oracle MySQL Connector/C (aka libmysqlclient) versions prior to 6.1.3, update to version 6.1.3 or later to resolve the issue. For MariaDB versions prior to 5.5.44, update to version 5.5.44 or later to resolve the issue.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1749
ALT-PU-2018-1647
CESA-2015_1665
CVE-2015-3152
DSA-3311-1
MGASA-2015-0279
OPENSUSE-SU-2015_1216-1
OPENSUSE-SU-2015_2243-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2015:1646
RHSA-2015:1647
RHSA-2015:1665
RHSA-2015_1665
SUSE-SU-2015:1273-1
SUSE-SU-2015:1788-1
SUSE-SU-2016:1638-1

Affected Products

Alt Linux
Centos
Mariadb
Mariadb Server
Mysql Server
Mysql Connector/J
Red Hat
Suse