CVE Vulnerabilities

CVE-2016-2047

Published: Jan 27, 2016 | Modified: Dec 27, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a /CN= string in a field in a certificate, as demonstrated by /OU=/CN=bar.com/CN=foo.com.

Affected Software

Name Vendor Start Version End Version
Mariadb Mariadb 5.5.20 (including) 5.5.47 (excluding)
Mariadb Mariadb 10.0.0 (including) 10.0.23 (excluding)
Mariadb Mariadb 10.1.0 (including) 10.1.10 (excluding)
Red Hat Enterprise Linux 7 RedHat mariadb-1:5.5.47-1.el7_2 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-mysql56-mysql-0:5.6.30-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-mariadb100-mariadb-1:10.0.25-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat mysql55-mysql-0:5.5.50-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat mariadb55-mariadb-0:5.5.49-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-mysql56-mysql-0:5.6.30-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-mariadb100-mariadb-1:10.0.25-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat mysql55-mysql-0:5.5.50-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat mariadb55-mariadb-0:5.5.49-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-mysql56-mysql-0:5.6.30-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-mariadb100-mariadb-1:10.0.25-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat mysql55-mysql-0:5.5.50-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat mariadb55-mariadb-0:5.5.49-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mysql56-mysql-0:5.6.30-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb100-mariadb-1:10.0.25-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat mysql55-mysql-0:5.5.50-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat mariadb55-mariadb-0:5.5.49-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-mysql56-mysql-0:5.6.30-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-mariadb100-mariadb-1:10.0.25-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat mysql55-mysql-0:5.5.50-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat mariadb55-mariadb-0:5.5.49-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-mysql56-mysql-0:5.6.30-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-mariadb100-mariadb-1:10.0.25-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat mysql55-mysql-0:5.5.50-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat mariadb55-mariadb-0:5.5.49-1.el7 *
Mariadb-10.0 Ubuntu upstream *
Mariadb-10.0 Ubuntu vivid *
Mariadb-10.0 Ubuntu wily *
Mariadb-5.5 Ubuntu trusty *
Mariadb-5.5 Ubuntu upstream *
Mysql-5.5 Ubuntu precise *
Mysql-5.5 Ubuntu trusty *
Mysql-5.5 Ubuntu upstream *
Mysql-5.6 Ubuntu trusty *
Mysql-5.6 Ubuntu upstream *
Mysql-5.6 Ubuntu wily *
Mysql-5.7 Ubuntu artful *
Mysql-5.7 Ubuntu bionic *
Mysql-5.7 Ubuntu cosmic *
Mysql-5.7 Ubuntu disco *
Mysql-5.7 Ubuntu upstream *
Mysql-5.7 Ubuntu xenial *
Mysql-5.7 Ubuntu yakkety *
Mysql-5.7 Ubuntu zesty *
Percona-server-5.6 Ubuntu artful *
Percona-server-5.6 Ubuntu esm-apps/xenial *
Percona-server-5.6 Ubuntu vivid *
Percona-server-5.6 Ubuntu wily *
Percona-server-5.6 Ubuntu xenial *
Percona-server-5.6 Ubuntu yakkety *
Percona-server-5.6 Ubuntu zesty *
Percona-xtradb-cluster-5.5 Ubuntu trusty *
Percona-xtradb-cluster-5.6 Ubuntu vivid *
Percona-xtradb-cluster-5.6 Ubuntu wily *
Percona-xtradb-cluster-5.6 Ubuntu xenial *
Percona-xtradb-cluster-5.6 Ubuntu yakkety *

References