CVE-2015-3152
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 16 May 2016, 10:00
Last modified:06 Aug 2024, 05:39
Vulnerability Summary
Overall Risk (default)
medium
42/100 CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
39.69% HIGH
40% probability -12.56%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
16 May 2016, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 05:39
Last Modified
Vulnerability information updated
Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 39.69%• Percentile: 97%
Techniques & Countermeasures
- CWE-295•Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
Affected Systems
- debian•debian_linux
8.0
- fedoraproject•fedora
21 | 22
- mariadb•mariadb
≥ 5.5.0, < 5.5.44 | ≥ 10.0.0, < 10.0.20
- oracle•mysql
≤ 5.7.2
- oracle•mysql_connector\/c
≤ 6.1.2
- Unknown•PHP
≥ 5.4.0, < 5.4.43 | ≥ 5.5.0, < 5.5.27 | ≥ 5.6.0, < 5.6.11
- redhat•enterprise_linux_desktop
7.0
- redhat•enterprise_linux_eus
7.1 | 7.2 | 7.3 | 7.4 | 7.5 | 7.6 | 7.7
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_server_aus
7.3 | 7.4 | 7.6 | 7.7
- redhat•enterprise_linux_server_tus
7.3 | 7.6 | 7.7
- redhat•enterprise_linux_workstation
7.0
References (17)
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.html
- http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/
- http://www.securityfocus.com/bid/74398
- https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390
- https://access.redhat.com/security/cve/cve-2015-3152
- http://rhn.redhat.com/errata/RHSA-2015-1646.html
- http://www.debian.org/security/2015/dsa-3311
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/
- http://rhn.redhat.com/errata/RHSA-2015-1647.html
- http://www.securitytracker.com/id/1032216
- https://www.duosecurity.com/blog/backronym-mysql-vulnerability
- https://jira.mariadb.org/browse/MDEV-7937
- http://www.ocert.org/advisories/ocert-2015-003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.html
- http://www.securityfocus.com/archive/1/535397/100/1100/threaded
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.html
- http://rhn.redhat.com/errata/RHSA-2015-1665.html