CVE-2015-3152
Last modified
CVE-2015-3152 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.. EPSS estimates a 7.08% chance of exploitation in the next 30 days.
Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | <= 5.7.2 |
| Oracle | Mysql Connector\/C | <= 6.1.2 |
| Mariadb | Mariadb | >= 5.5.0, < 5.5.44 |
| Mariadb | Mariadb | >= 10.0.0, < 10.0.20 |
| Fedoraproject | Fedora | 21 |
| Fedoraproject | Fedora | 22 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 7.1 |
| Redhat | Enterprise Linux Eus | 7.2 |
| Redhat | Enterprise Linux Eus | 7.3 |
| Redhat | Enterprise Linux Eus | 7.4 |
| Redhat | Enterprise Linux Eus | 7.5 |
| Redhat | Enterprise Linux Eus | 7.6 |
| Redhat | Enterprise Linux Eus | 7.7 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Aus | 7.7 |
| Redhat | Enterprise Linux Server Tus | 7.3 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.7 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Php | Php | >= 5.4.0, < 5.4.43 |
| Php | Php | >= 5.5.0, < 5.5.27 |
| Php | Php | >= 5.6.0, < 5.6.11 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlMailing List, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1646.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.ocert.org/advisories/ocert-2015-003.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/535397/100/1100/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74398Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032216Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2015-3152Third Party Advisory
- https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390Patch, Third Party Advisory
- https://jira.mariadb.org/browse/MDEV-7937Issue Tracking, Vendor Advisory
- https://www.duosecurity.com/blog/backronym-mysql-vulnerabilityThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161436.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161625.htmlMailing List, Third Party Advisory
- http://mysqlblog.fivefarmers.com/2014/04/02/redefining-ssl-option/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/131688/MySQL-SSL-TLS-Downgrade.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1646.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.ocert.org/advisories/ocert-2015-003.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/535397/100/1100/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74398Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032216Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2015-3152Third Party Advisory
- https://github.com/mysql/mysql-server/commit/3bd5589e1a5a93f9c224badf983cd65c45215390Patch, Third Party Advisory
- https://jira.mariadb.org/browse/MDEV-7937Issue Tracking, Vendor Advisory
- https://www.duosecurity.com/blog/backronym-mysql-vulnerabilityThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3152?
How severe is CVE-2015-3152?
How do I fix CVE-2015-3152?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-3146The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet h…
- CVE-2015-3147daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool…6.5
- CVE-2015-3148cURL and libcurl 7.10.6 through 7.41.0 do not properly re-us…
- CVE-2015-3149The Hotspot component in OpenJDK8 as packaged in Red Hat Ent…
- CVE-2015-3150abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows loca…7.1
- CVE-2015-3151Directory traversal vulnerability in abrt-dbus in Automatic …7.8
- CVE-2015-3153The default configuration for cURL and libcurl before 7.42.1…
- CVE-2015-3154CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zen…6.1
- CVE-2015-3155Foreman before 1.8.1 does not set the secure flag for the _s…
- CVE-2015-3156The _write_config function in trove/guestagent/datastore/exp…
- CVE-2015-3157Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-3158The invokeNextValve function in identity/federation/bindings…
Are you affected by CVE-2015-3152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
