CVE-2015-3152
16.05.2016, 10:59
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.Enginsight
Vendor | Product | Version |
---|---|---|
oracle | mysql | 𝑥 ≤ 5.7.2 |
oracle | mysql_connector\/c | 𝑥 ≤ 6.1.2 |
mariadb | mariadb | 5.5.0 ≤ 𝑥 < 5.5.44 |
mariadb | mariadb | 10.0.0 ≤ 𝑥 < 10.0.20 |
debian | debian_linux | 8.0 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_eus | 7.1 |
redhat | enterprise_linux_eus | 7.2 |
redhat | enterprise_linux_eus | 7.3 |
redhat | enterprise_linux_eus | 7.4 |
redhat | enterprise_linux_eus | 7.5 |
redhat | enterprise_linux_eus | 7.6 |
redhat | enterprise_linux_eus | 7.7 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.4 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_aus | 7.7 |
redhat | enterprise_linux_server_tus | 7.3 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_server_tus | 7.7 |
redhat | enterprise_linux_workstation | 7.0 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.43 |
php | php | 5.5.0 ≤ 𝑥 < 5.5.27 |
php | php | 5.6.0 ≤ 𝑥 < 5.6.11 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mariadb-10.0 |
| ||||||||||||||||||||||||||||||||||||||||||
mariadb-5.5 |
| ||||||||||||||||||||||||||||||||||||||||||
mysql-5.5 |
| ||||||||||||||||||||||||||||||||||||||||||
mysql-5.6 |
| ||||||||||||||||||||||||||||||||||||||||||
mysql-dfsg-5.1 |
| ||||||||||||||||||||||||||||||||||||||||||
percona-server-5.6 |
| ||||||||||||||||||||||||||||||||||||||||||
percona-xtradb-cluster-5.5 |
|
Common Weakness Enumeration
References