CVE-2015-3152
published 2016-05-16CVE-2015-3152: Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is…
PriorityP333medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
7.08%
93.5th percentile
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dbd-mysql_project | dbd-mysql | <= 4.043 | — |
| debian | debian_linux | — | — |
| debian | libdbd-mysql-perl | < libdbd-mysql-perl 4.046-1 (bookworm) | libdbd-mysql-perl 4.046-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | >= 10.0.0 < 10.0.20 | 10.0.20 |
| mariadb | mariadb | >= 5.5.0 < 5.5.44 | 5.5.44 |
| oracle | mysql | <= 5.7.2 | — |
| oracle | mysql_connector_c | <= 6.1.2 | — |
| php | php | <= 5.4.42 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqmm-72rw-vrp2: ext/mysqlnd/mysqlnd
ghsa_unreviewed·2022-05-17·CVSS 5.9
CVE-2015-8838 [MEDIUM] CWE-284 GHSA-gqmm-72rw-vrp2: ext/mysqlnd/mysqlnd
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
GHSA
GHSA-p7qr-v5jx-7qv3: Oracle MySQL before 5
ghsa_unreviewed·2022-05-14
CVE-2015-3152 [MEDIUM] CWE-284 GHSA-p7qr-v5jx-7qv3: Oracle MySQL before 5
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
GHSA
GHSA-4384-9v4p-2vmf: The DBD::mysql module through 4
ghsa_unreviewed·2022-05-13·CVSS 5.9
CVE-2017-10789 [MEDIUM] GHSA-4384-9v4p-2vmf: The DBD::mysql module through 4
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
OSV
CVE-2017-10789: The DBD::mysql module through 4
osv·2017-07-01·CVSS 5.9
CVE-2017-10789 [MEDIUM] CVE-2017-10789: The DBD::mysql module through 4
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
OSV
CVE-2015-3152: Oracle MySQL before 5
osv·2016-05-16·CVSS 5.9
CVE-2015-3152 [MEDIUM] CVE-2015-3152: Oracle MySQL before 5
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
OSV
CVE-2015-8838: ext/mysqlnd/mysqlnd
osv·2015-12-31·CVSS 5.9
CVE-2015-8838 [MEDIUM] CVE-2015-8838: ext/mysqlnd/mysqlnd
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Red Hat
perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
vendor_redhat·2017-07-01·CVSS 5.9
CVE-2017-10789 [MEDIUM] CWE-300 perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 5) - Will not fix
Package: perl-DBD-MySQL (Red Hat E
Debian
CVE-2017-10789: libdbd-mysql-perl - The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mea...
vendor_debian·2017·CVSS 5.9
CVE-2017-10789 [MEDIUM] CVE-2017-10789: libdbd-mysql-perl - The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mea...
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Scope: local
bookworm: resolved (fixed in 4.046-1)
bullseye: resolved (fixed in 4.046-1)
forky: resolved (fixed in 4.046-1)
sid: resolved (fixed in 4.046-1)
trixie: resolved (fixed in 4.046-1)
Red Hat
php: mysqlnd interface vulnerable to BACKRONYM
vendor_redhat·2015-05-20·CVSS 5.9
CVE-2015-8838 [MEDIUM] php: mysqlnd interface vulnerable to BACKRONYM
php: mysqlnd interface vulnerable to BACKRONYM
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collections) - Will not fix
Package: rh-php56-php (Red Hat Software Collections) - Affected
Red Hat
mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
vendor_redhat·2015-04-29·CVSS 5.9
CVE-2015-3152 [MEDIUM] mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
It was found that the MySQL client library permitted but did not require a client to use SSL/TLS when establishing a secure connection to a MySQL server using the "--ssl" option. A man-in-the-middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Will not fix
Package: mysql (Red Hat Enterprise Linux 6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-2767 mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM)
bugzilla·2018-04-09·CVSS 5.9
CVE-2018-2767 [MEDIUM] CVE-2018-2767 mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM)
CVE-2018-2767 mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM)
MySQL 5.5, MariaDB 5.5 and 10.3 have a vulnerability in the client library that does not enforce the use of SSL/TLS. Client applications that specify the use of SSL/TLS can result in established connections without SSL/TLS enabled and no reported error.
This is the result of an incomplete fix for CVE-2015-3152 (a.k.a BACKRONYM).
Reference:
http://www.openwall.com/lists/oss-security/2018/04/08/2
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1564967]
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1564966]
---
In reply to comment 0:
> MySQL 5.5, MariaDB 5.5 and 10.3 have a vulnerability in the client library
> that does not enforc
Bugzilla
CVE-2017-10789 perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
bugzilla·2017-07-04·CVSS 5.9
CVE-2017-10789 [MEDIUM] CVE-2017-10789 perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
CVE-2017-10789 perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Upstream bug:
https://github.com/perl5-dbi/DBD-mysql/issues/140
Discussion:
Created perl-DBD-MySQL tracking bugs for this issue:
Affects: fedora-all [bug 1467608]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue
Bugzilla
CVE-2017-3305 mysql: incorrect enforcement of ssl-mode=REQUIRED in MySQL 5.5 and 5.6
bugzilla·2017-03-13·CVSS 5.9
CVE-2017-3305 [MEDIUM] CVE-2017-3305 mysql: incorrect enforcement of ssl-mode=REQUIRED in MySQL 5.5 and 5.6
CVE-2017-3305 mysql: incorrect enforcement of ssl-mode=REQUIRED in MySQL 5.5 and 5.6
It was found that MySQL client when specified to use SSL/TLS mode is authenticating to MySQL server not supporting SSL/TLS, client will fallback to plain text protocol used for authentication. After successful authentication client checks if SSL/TLS layer is required and if server doesn't support it, client will close the connection with error.
Active MITM attacker can downgrade SSL/TLS to plain text and forward nonce from server back to client. MITM attacker receive login data (for server nonce) from client and send it to server to authenticate as client.
This issue is present in libmysqlclient.so in 5.5 and 5.6 versions.
Discussion:
Acknowledgments:
Name: Pali Rohár
---
I think this is better des
Bugzilla
CVE-2015-3152 mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
bugzilla·2015-04-30·CVSS 5.9
CVE-2015-3152 [MEDIUM] CVE-2015-3152 mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
CVE-2015-3152 mysql: use of SSL/TLS can not be enforced in mysql client library (oCERT-2015-003, BACKRONYM)
oCERT released the following advisory regarding MySQL:
A vulnerability has been reported concerning the impossibility for MySQL users (with any major stable version) to enforce an effective SSL/TLS connection that would be immune from man-in-the-middle (MITM) attacks performing a malicious downgrade.
While the issue has been addressed in MySQL preview release 5.7.3 in December 2013, it is perceived that the majority of MySQL users are not aware of this limitation and that the issue should be treated as a vulnerability.
The vulnerability lies within the behaviour of the '--ssl' client option, which on affected versions it is being treated as "advisory". Therefore while the option
Bugzilla
CVE-2015-3152 community-mysql: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
bugzilla·2015-04-30·CVSS 5.9
CVE-2015-3152 [MEDIUM] CVE-2015-3152 community-mysql: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
CVE-2015-3152 community-mysql: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2015-3152 mariadb: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
bugzilla·2015-04-30·CVSS 5.9
CVE-2015-3152 [MEDIUM] CVE-2015-3152 mariadb: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
CVE-2015-3152 mariadb: mysql: SSL/TLS downgrade (oCERT-2015-003) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlhttp://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1646.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1647.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1665.htmlhttp://www.debian.org/security/2015/dsa-3311http://www.ocert.org/advisories/ocert-2015-003.htmlhttp://www.securityfocus.com/archive/1/535397/100/1100/threadedhttp://www.securityfocus.com/bid/74398http://www.securitytracker.com/id/1032216https://access.redhat.com/security/cve/cve-2015-3152https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390https://jira.mariadb.org/browse/MDEV-7937https://www.duosecurity.com/blog/backronym-mysql-vulnerabilityhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlhttp://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1646.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1647.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1665.htmlhttp://www.debian.org/security/2015/dsa-3311http://www.ocert.org/advisories/ocert-2015-003.htmlhttp://www.securityfocus.com/archive/1/535397/100/1100/threadedhttp://www.securityfocus.com/bid/74398http://www.securitytracker.com/id/1032216https://access.redhat.com/security/cve/cve-2015-3152https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390https://jira.mariadb.org/browse/MDEV-7937https://www.duosecurity.com/blog/backronym-mysql-vulnerability
2016-05-16
Published