The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a /CN= string in a field in a certificate, as demonstrated by /OU=/CN=bar.com/CN=foo.com.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mariadb | Mariadb | 5.5.20 (including) | 5.5.47 (excluding) |
Mariadb | Mariadb | 10.0.0 (including) | 10.0.23 (excluding) |
Mariadb | Mariadb | 10.1.0 (including) | 10.1.10 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | mariadb-1:5.5.47-1.el7_2 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mysql56-mysql-0:5.6.30-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | mysql55-mysql-0:5.5.50-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | mariadb55-mariadb-0:5.5.49-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | rh-mysql56-mysql-0:5.6.30-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | mysql55-mysql-0:5.5.50-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | mariadb55-mariadb-0:5.5.49-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mysql56-mysql-0:5.6.30-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | mysql55-mysql-0:5.5.50-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | mariadb55-mariadb-0:5.5.49-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mysql56-mysql-0:5.6.30-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | mysql55-mysql-0:5.5.50-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | mariadb55-mariadb-0:5.5.49-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-mysql56-mysql-0:5.6.30-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | mysql55-mysql-0:5.5.50-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | mariadb55-mariadb-0:5.5.49-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-mysql56-mysql-0:5.6.30-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.25-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | mysql55-mysql-0:5.5.50-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | mariadb55-mariadb-0:5.5.49-1.el7 | * |
Mariadb-10.0 | Ubuntu | upstream | * |
Mariadb-10.0 | Ubuntu | vivid | * |
Mariadb-10.0 | Ubuntu | wily | * |
Mariadb-5.5 | Ubuntu | trusty | * |
Mariadb-5.5 | Ubuntu | upstream | * |
Mysql-5.5 | Ubuntu | precise | * |
Mysql-5.5 | Ubuntu | trusty | * |
Mysql-5.5 | Ubuntu | upstream | * |
Mysql-5.6 | Ubuntu | trusty | * |
Mysql-5.6 | Ubuntu | upstream | * |
Mysql-5.6 | Ubuntu | wily | * |
Mysql-5.7 | Ubuntu | artful | * |
Mysql-5.7 | Ubuntu | bionic | * |
Mysql-5.7 | Ubuntu | cosmic | * |
Mysql-5.7 | Ubuntu | disco | * |
Mysql-5.7 | Ubuntu | upstream | * |
Mysql-5.7 | Ubuntu | xenial | * |
Mysql-5.7 | Ubuntu | yakkety | * |
Mysql-5.7 | Ubuntu | zesty | * |
Percona-server-5.6 | Ubuntu | artful | * |
Percona-server-5.6 | Ubuntu | esm-apps/xenial | * |
Percona-server-5.6 | Ubuntu | vivid | * |
Percona-server-5.6 | Ubuntu | wily | * |
Percona-server-5.6 | Ubuntu | xenial | * |
Percona-server-5.6 | Ubuntu | yakkety | * |
Percona-server-5.6 | Ubuntu | zesty | * |
Percona-xtradb-cluster-5.5 | Ubuntu | trusty | * |
Percona-xtradb-cluster-5.6 | Ubuntu | vivid | * |
Percona-xtradb-cluster-5.6 | Ubuntu | wily | * |
Percona-xtradb-cluster-5.6 | Ubuntu | xenial | * |
Percona-xtradb-cluster-5.6 | Ubuntu | yakkety | * |