Описание
libmariadb allowed cleartext password leakage on TLS hostname verification failure
Impact
In the Zero-Configuration SSL protocol, the MariaDB client must refuse sending clear-text password over unverified TLS connection. Because of a programming mistake, MariaDB Connector/C (libmariadb) could have switched to a clear-text password plugin if the TLS certificate was valid, but did not belong to the connecting host. This allowed an active man-in-the-middle attacker to replace the certificate to another valid certificate and request the client to switch to the clear-text password plugin. Only MariaDB Connector/C is affected, other MariaDB connectors are safe.
Workarounds
Any of the below can be used as mitigation
- install properly signed certificates on the server
- configure the client to accept only specific certificate fingerprints
- delete
mysql_clear_password.soanddialog.sofiles - use
restricted-authoption to restrict authentication to safe subset of plugins
References
https://jira.mariadb.org/browse/CONC-846
Credits
Aisle Research RedHat
Пакеты
mariadb
>=3.4.1, <=3.4.9
3.4.10
5.9 Medium
CVSS3
Дефекты
5.9 Medium
CVSS3