CVE-2015-3152

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:mysql_connector\/c:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Information

Published : 2016-05-16 10:59

Updated : 2018-10-09 19:56


NVD link : CVE-2015-3152

Mitre link : CVE-2015-3152


JSON object : View

Products Affected

oracle

  • mysql_connector\/c
  • mysql

mariadb

  • mariadb
CWE
CWE-284

Improper Access Control