Логотип exploitDog
bind:"GHSA-gw5g-54qg-7583" OR bind:"CVE-2016-2047"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-gw5g-54qg-7583" OR bind:"CVE-2016-2047"

Количество 13

Количество 13

github логотип

GHSA-gw5g-54qg-7583

больше 3 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-2047

больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2016-2047

больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2016-2047

больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2016-2047

больше 9 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1279-1

больше 9 лет назад

Security update for mysql

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:1332-1

больше 9 лет назад

Security update for mysql-community-server

EPSS: Низкий
oracle-oval логотип

ELSA-2016-0534

больше 9 лет назад

ELSA-2016-0534: mariadb security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:1686-1

около 9 лет назад

Security update for mariadb

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1620-1

около 9 лет назад

Security update for mariadb

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1619-1

около 9 лет назад

Security update for mariadb

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2023:4991-1

больше 1 года назад

Recommended update for mariadb104

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2023:3956-1

почти 2 года назад

Recommended update for mariadb104

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gw5g-54qg-7583

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS2: 4.9
2%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
2%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB ...

CVSS3: 5.9
2%
Низкий
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1279-1

Security update for mysql

больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1332-1

Security update for mysql-community-server

больше 9 лет назад
oracle-oval логотип
ELSA-2016-0534

ELSA-2016-0534: mariadb security and bug fix update (MODERATE)

больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1686-1

Security update for mariadb

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1620-1

Security update for mariadb

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1619-1

Security update for mariadb

около 9 лет назад
suse-cvrf логотип
SUSE-RU-2023:4991-1

Recommended update for mariadb104

больше 1 года назад
suse-cvrf логотип
SUSE-RU-2023:3956-1

Recommended update for mariadb104

почти 2 года назад

Уязвимостей на страницу