5.9

CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MariadbMariadb Version >= 5.5.20 < 5.5.47
MariadbMariadb Version >= 10.0.0 < 10.0.23
MariadbMariadb Version >= 10.1.0 < 10.1.10
OracleLinux Version7
OracleMysql Version >= 5.5.0 <= 5.5.48
OracleMysql Version >= 5.6.0 <= 5.6.29
OracleMysql Version >= 5.7.0 <= 5.7.11
OpensuseLeap Version42.1
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version7.0
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.10
CanonicalUbuntu Linux Version16.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.69% 0.854
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
http://www.securityfocus.com/bid/81810
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1035606
Third Party Advisory
VDB Entry