CVE Vulnerabilities

CVE-2016-2047

Published: Jan 27, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a /CN= string in a field in a certificate, as demonstrated by /OU=/CN=bar.com/CN=foo.com.

Affected Software

NameVendorStart VersionEnd Version
MariadbMariadb5.5.20 (including)5.5.47 (excluding)
MariadbMariadb10.0.0 (including)10.0.23 (excluding)
MariadbMariadb10.1.0 (including)10.1.10 (excluding)
Red Hat Enterprise Linux 7RedHatmariadb-1:5.5.47-1.el7_2*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mysql56-mysql-0:5.6.30-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mariadb100-mariadb-1:10.0.25-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatmysql55-mysql-0:5.5.50-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatmariadb55-mariadb-0:5.5.49-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-mysql56-mysql-0:5.6.30-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-mariadb100-mariadb-1:10.0.25-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatmysql55-mysql-0:5.5.50-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatmariadb55-mariadb-0:5.5.49-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-mysql56-mysql-0:5.6.30-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-mariadb100-mariadb-1:10.0.25-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatmysql55-mysql-0:5.5.50-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatmariadb55-mariadb-0:5.5.49-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mysql56-mysql-0:5.6.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb100-mariadb-1:10.0.25-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatmysql55-mysql-0:5.5.50-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatmariadb55-mariadb-0:5.5.49-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-mysql56-mysql-0:5.6.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-mariadb100-mariadb-1:10.0.25-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatmysql55-mysql-0:5.5.50-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatmariadb55-mariadb-0:5.5.49-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-mysql56-mysql-0:5.6.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-mariadb100-mariadb-1:10.0.25-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatmysql55-mysql-0:5.5.50-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatmariadb55-mariadb-0:5.5.49-1.el7*
Mariadb-10.0Ubuntuupstream*
Mariadb-10.0Ubuntuvivid*
Mariadb-10.0Ubuntuwily*
Mariadb-5.5Ubuntutrusty*
Mariadb-5.5Ubuntuupstream*
Mysql-5.5Ubuntuesm-infra-legacy/trusty*
Mysql-5.5Ubuntuprecise*
Mysql-5.5Ubuntutrusty*
Mysql-5.5Ubuntutrusty/esm*
Mysql-5.5Ubuntuupstream*
Mysql-5.6Ubuntutrusty*
Mysql-5.6Ubuntuupstream*
Mysql-5.6Ubuntuwily*
Mysql-5.7Ubuntuartful*
Mysql-5.7Ubuntubionic*
Mysql-5.7Ubuntucosmic*
Mysql-5.7Ubuntudisco*
Mysql-5.7Ubuntuesm-infra/bionic*
Mysql-5.7Ubuntuesm-infra/xenial*
Mysql-5.7Ubuntuupstream*
Mysql-5.7Ubuntuxenial*
Mysql-5.7Ubuntuyakkety*
Mysql-5.7Ubuntuzesty*
Percona-server-5.6Ubuntuartful*
Percona-server-5.6Ubuntuesm-apps/xenial*
Percona-server-5.6Ubuntuvivid*
Percona-server-5.6Ubuntuwily*
Percona-server-5.6Ubuntuxenial*
Percona-server-5.6Ubuntuyakkety*
Percona-server-5.6Ubuntuzesty*
Percona-xtradb-cluster-5.5Ubuntutrusty*
Percona-xtradb-cluster-5.6Ubuntuesm-apps/xenial*
Percona-xtradb-cluster-5.6Ubuntuvivid*
Percona-xtradb-cluster-5.6Ubuntuwily*
Percona-xtradb-cluster-5.6Ubuntuxenial*
Percona-xtradb-cluster-5.6Ubuntuyakkety*

References