« List of all CVEs

CVE-2015-3152

Published: 5/16/2016 Last updated: 8/6/2024 Reserved: 4/10/2015

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-mariadb conf-mysql

Products affected (1)

Product Vendor Version
n/a n/a <= 6.11.*

References (34)