Vulnerability Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | <= 5.7.2 |
| Oracle | Mysql Connector\/C | <= 6.1.2 |
| Mariadb | Mariadb | >= 5.5.0, < 5.5.44 |
| Fedoraproject | Fedora | 21 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 7.1 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Tus | 7.3 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Php | Php | >= 5.4.0, < 5.4.43 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlMailing ListThird Party Advisory
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/ExploitThird Party Advisory
- http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisoryThird Party Advisory
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1646.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.ocert.org/advisories/ocert-2015-003.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/535397/100/1100/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/74398Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032216Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/cve-2015-3152Third Party Advisory
- https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c452PatchThird Party Advisory
FAQ
What is CVE-2015-3152?
CVE-2015-3152 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attac...
How severe is CVE-2015-3152?
CVE-2015-3152 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3152?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql, Oracle Mysql Connector\/C, Mariadb Mariadb, Fedoraproject Fedora, Debian Debian Linux.