CVE-2015-3152: Debian Linux
Medium severity, CVSS 5.9. EPSS: 7.1% chance of exploitation in the next 30 days.
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 21 only; version 22 only
- MariaDB MariaDB: from 5.5.0, before 5.5.44 (fixed in 5.5.44); from 10.0.0, before 10.0.20 (fixed in 10.0.20)
- Oracle MySQL: up to and including 5.7.2
- Oracle MySQL Connector/c: up to and including 6.1.2
- PHP PHP: from 5.4.0, before 5.4.43 (fixed in 5.4.43); from 5.5.0, before 5.5.27 (fixed in 5.5.27); from 5.6.0, before 5.6.11 (fixed in 5.6.11)
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2016-05-16. Last modified 2026-06-17.