CVE-2015-3152

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.

References

http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.html

http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/

http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/

http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.html

http://rhn.redhat.com/errata/RHSA-2015-1646.html

http://rhn.redhat.com/errata/RHSA-2015-1647.html

http://rhn.redhat.com/errata/RHSA-2015-1665.html

http://www.debian.org/security/2015/dsa-3311

http://www.ocert.org/advisories/ocert-2015-003.html

http://www.securityfocus.com/archive/1/535397/100/1100/threaded

http://www.securityfocus.com/bid/74398

http://www.securitytracker.com/id/1032216

https://access.redhat.com/security/cve/cve-2015-3152

https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390

https://jira.mariadb.org/browse/MDEV-7937

https://www.duosecurity.com/blog/backronym-mysql-vulnerability

Details

Source: MITRE

Published: 2016-05-16

Updated: 2018-10-09

Type: CWE-284

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 2.2

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions up to 5.7.2 (inclusive)

cpe:2.3:a:oracle:mysql_connector\/c:*:*:*:*:*:*:*:* versions up to 6.1.2 (inclusive)

Configuration 2

OR

cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions up to 5.5.43 (inclusive)

Tenable Plugins

View all (34 total)

IDNameProductFamilySeverity
125007EulerOS Virtualization 3.0.1.0 : mariadb (EulerOS-SA-2019-1554)NessusHuawei Local Security Checks
high
98803PHP 5.6.x < 5.6.11 Multiple Vulnerabilities (BACKRONYM)Web Application ScanningComponent Vulnerability
critical
111708F5 Networks BIG-IP : MySQL vulnerability (K16845) (BACKRONYM)NessusF5 Networks Local Security Checks
medium
110214openSUSE Security Update : perl-DBD-mysql (openSUSE-2018-539) (BACKRONYM)NessusSuSE Local Security Checks
critical
110188SUSE SLES12 Security Update : perl-DBD-mysql (SUSE-SU-2018:1450-1) (BACKRONYM)NessusSuSE Local Security Checks
critical
110187SUSE SLES11 Security Update : perl-DBD-mysql (SUSE-SU-2018:1449-1) (BACKRONYM)NessusSuSE Local Security Checks
critical
106496pfSense < 2.2.4 Multiple Vulnerabilities (SA-15_07)NessusFirewalls
medium
93161SUSE SLES11 Security Update : php53 (SUSE-SU-2016:1638-1) (BACKRONYM)NessusSuSE Local Security Checks
critical
9303MariaDB Server 10.0.x < 10.0.22 / 10.1.x < 10.1.9 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
9302MariaDB Server 5.4.x < 5.4.46 / 10.0.x < 10.0.22 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
9282MariaDB Server 10.0.x < 10.0.20 Multiple Vulnerabilities (BACKRONYM) Nessus Network MonitorDatabase
medium
87442openSUSE Security Update : mysql (openSUSE-2015-889) (BACKRONYM)NessusSuSE Local Security Checks
high
86537SUSE SLED11 / SLES11 Security Update : mysql (SUSE-SU-2015:1788-1) (BACKRONYM)NessusSuSE Local Security Checks
medium
8955PHP 5.5.x < 5.5.27 / 5.6.x < 5.6.11 Multiple Vulnerabilities Nessus Network MonitorWeb Servers
high
8954PHP 5.6.10 < 5.6.11 Multiple Vulnerabilities (BACKRONYM)Nessus Network MonitorWeb Servers
high
85635CentOS 7 : mariadb (CESA-2015:1665) (BACKRONYM)NessusCentOS Local Security Checks
medium
85622Scientific Linux Security Update : mariadb on SL7.x x86_64 (20150824) (BACKRONYM)NessusScientific Linux Local Security Checks
medium
85616RHEL 7 : mariadb (RHSA-2015:1665) (BACKRONYM)NessusRed Hat Local Security Checks
medium
85612Oracle Linux 7 : mariadb (ELSA-2015-1665) (BACKRONYM)NessusOracle Linux Local Security Checks
medium
85458Amazon Linux AMI : php56 (ALAS-2015-585) (BACKRONYM)NessusAmazon Linux Local Security Checks
critical
85457Amazon Linux AMI : php55 (ALAS-2015-584) (BACKRONYM)NessusAmazon Linux Local Security Checks
critical
85456Amazon Linux AMI : php54 (ALAS-2015-583) (BACKRONYM)NessusAmazon Linux Local Security Checks
critical
84913SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2015:1273-1) (BACKRONYM)NessusSuSE Local Security Checks
high
84839Debian DSA-3311-1 : mariadb-10.0 - security update (BACKRONYM)NessusDebian Local Security Checks
medium
84830Slackware 14.0 / 14.1 / current : php (SSA:2015-198-02) (BACKRONYM)NessusSlackware Local Security Checks
critical
84796MariaDB 10.0.x < 10.0.20 Multiple Vulnerabilities (BACKRONYM)NessusDatabases
medium
84696FreeBSD : mysql -- SSL Downgrade (36bd352d-299b-11e5-86ff-14dae9d210b8) (BACKRONYM)NessusFreeBSD Local Security Checks
medium
84680Fedora 21 : mariadb-10.0.20-1.fc21 (2015-10831) (BACKRONYM)NessusFedora Local Security Checks
medium
84658openSUSE Security Update : MariaDB (openSUSE-2015-479) (BACKRONYM) (Logjam)NessusSuSE Local Security Checks
high
84673PHP 5.6.x < 5.6.11 Multiple Vulnerabilities (BACKRONYM)NessusCGI abuses
critical
84672PHP 5.5.x < 5.5.27 Multiple Vulnerabilities (BACKRONYM)NessusCGI abuses
critical
84671PHP 5.4.x < 5.4.43 Multiple Vulnerabilities (BACKRONYM)NessusCGI abuses
critical
84521Fedora 22 : mariadb-10.0.20-1.fc22 (2015-10849) (BACKRONYM)NessusFedora Local Security Checks
medium
83347MySQL 5.1.x < 5.7.3 SSL/TLS Downgrade MitM (BACKRONYM)NessusDatabases
medium