Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
References
Information
Published : 2016-05-16 10:59
Updated : 2018-10-09 19:56
NVD link : CVE-2015-3152
Mitre link : CVE-2015-3152
JSON object : View
Products Affected
oracle
- mysql_connector\/c
- mysql
mariadb
- mariadb
CWE
CWE-284
Improper Access Control
