CVE Database
/

CVE-2016-2047

Back to search

CVE-2016-2047

Published: Jan 27, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2016:1620
vendor-advisory
x_refsource_SUSE
RHSA-2016:1481
vendor-advisory
x_refsource_REDHAT
RHSA-2016:1132
vendor-advisory
x_refsource_REDHAT
RHSA-2016:0534
vendor-advisory
x_refsource_REDHAT
1035606
vdb-entry
x_refsource_SECTRACK
USN-2953-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2016:1332
vendor-advisory
x_refsource_SUSE
USN-2954-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2016:1619
vendor-advisory
x_refsource_SUSE
RHSA-2016:1480
vendor-advisory
x_refsource_REDHAT
81810
vdb-entry
x_refsource_BID
openSUSE-SU-2016:1664
vendor-advisory
x_refsource_SUSE
DSA-3557
vendor-advisory
x_refsource_DEBIAN
DSA-3453
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2016:1686
vendor-advisory
x_refsource_SUSE
RHSA-2016:0705
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2016:1279
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now