vulnerability
Ubuntu: (CVE-2015-3152): mariadb-5.5 vulnerability
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:P/A:N) | May 16, 2016 | Nov 19, 2024 | May 27, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
May 16, 2016
Added
Nov 19, 2024
Modified
May 27, 2025
Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Solution(s)
ubuntu-upgrade-mariadb-10-0ubuntu-upgrade-mariadb-5-5
References
- CVE-2015-3152
- https://attackerkb.com/topics/CVE-2015-3152
- DEBIAN-DSA-3311
- URL-http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-3.html
- URL-http://mysqlblog.fivefarmers.com/2015/04/29/ssltls-in-5-6-and-5-5-ocert-advisory/
- URL-http://www.ocert.org/advisories/ocert-2015-003.html
- URL-https://www.cve.org/CVERecord?id=CVE-2015-3152

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.