CVE-2016-2047

CVSS v3.0 5.9 (Medium)
59% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.33 % (71th)
0.33% Progress
Affected Products 7
Advisories 14

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

Weaknesses
CWE-254
7PK - Security Features
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2016-01-27 20:59:05
(8 years ago)
Updated Date
2019-12-27 16:08:55
(4 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mariadb from 5.5.20 version and prior 5.5.47 version cpe:2.3:a:mariadb:mariadb >= 5.5.20 < 5.5.47
  Mariadb from 10.0.0 version and prior 10.0.23 version cpe:2.3:a:mariadb:mariadb >= 10.0.0 < 10.0.23
  Mariadb from 10.1.0 version and prior 10.1.10 version cpe:2.3:a:mariadb:mariadb >= 10.1.0 < 10.1.10

Configuration #2

    CPE23 From Up To
  Oracle Linux 7 cpe:2.3:o:oracle:linux:7

Configuration #3

    CPE23 From Up To
  Oracle Mysql from 5.5.0 version and 5.5.48 and prior versions cpe:2.3:a:oracle:mysql >= 5.5.0 <= 5.5.48
  Oracle Mysql from 5.6.0 version and 5.6.29 and prior versions cpe:2.3:a:oracle:mysql >= 5.6.0 <= 5.6.29
  Oracle Mysql from 5.7.0 version and 5.7.11 and prior versions cpe:2.3:a:oracle:mysql >= 5.7.0 <= 5.7.11

Configuration #4

    CPE23 From Up To
  Opensuse Leap 42.1 cpe:2.3:o:opensuse:leap:42.1

Configuration #5

    CPE23 From Up To
  Redhat Enterprise Linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0

Configuration #6

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #7

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...