The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libdbd-mysql-perl | Feb 25, 2019 | Jul 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | — | Feb 22, 2021 | Jul 1, 2017 |
| Huawei Euleros 2_0_sp3 | — | — | Apr 30, 2021 | Jul 1, 2017 |
| Huawei Euleros 2_0_sp5 | — | — | Feb 3, 2021 | Jul 1, 2017 |
| Oracle Solaris | — | Upgrade library/perl-5/dbd-mysql-522 to version 4048-11.4.3.0.1.4.0 on Solaris 11.4Upgrade library/perl-5/dbd-mysql to version 4048-11.4.3.0.1.4.0 on Solaris 11.4Upgrade library/perl-5/dbd-mysql-526 to version 4048-11.4.3.0.1.4.0 on Solaris 11.4 | Nov 19, 2018 | Jul 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 1, 2017 |
| Suse | — | Upgrade perl-DBD-mysql | May 29, 2018 | Jul 1, 2017 |
| Ubuntu | — | Upgrade libdbd-mysql-perl (Ubuntu Pro) | Mar 22, 2023 | Jul 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub