CVE-2015-3152

MEDIUM

Oracle MySQL <5.7.3 & MariaDB <5.5.44 - Info Disclosure

Title source: llm

Description

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.

Exploits (1)

nomisec WORKING POC 43 stars
by duo-labs · poc
https://github.com/duo-labs/mysslstrip

References (17)

Scores

CVSS v3 5.9
EPSS 0.5167
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-295
Status draft

Affected Products (24)

oracle/mysql < 5.7.2
oracle/mysql_connector\/c < 6.1.2
mariadb/mariadb < 5.5.44
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_server
... and 9 more

Timeline

Published May 16, 2016
Tracked Since Feb 18, 2026