Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2047

Опубликовано: 30 нояб. 2015
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

It was found that the MariaDB client library did not properly check host names against server identities noted in the X.509 certificates when establishing secure connections using TLS/SSL. A man-in-the-middle attacker could possibly use this flaw to impersonate a server to a client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5mysql55-mysqlWill not fix
Red Hat Enterprise Linux 6mysqlWill not fix
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)mariadb-galeraWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mariadb-galeraWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mariadb-galeraWill not fix
Red Hat OpenStack Platform 8 (Liberty)mariadb-galeraWill not fix
Red Hat Software Collectionsrh-mariadb101-mariadbNot affected
Red Hat Enterprise Linux 7mariadbFixedRHSA-2016:053431.03.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mysql56-mysqlFixedRHSA-2016:070502.05.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mariadb100-mariadbFixedRHSA-2016:113226.05.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1301874mysql: ssl-validate-cert incorrect hostname check

EPSS

Процентиль: 80%
0.0151
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
nvd
больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
debian
больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB ...

CVSS3: 5.9
github
больше 3 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

suse-cvrf
больше 9 лет назад

Security update for mysql

EPSS

Процентиль: 80%
0.0151
Низкий

4.9 Medium

CVSS2