mysqlnd is vulnerable to BACKRONYM (CVE-2015-8838)

Bug #1564388 reported by Mauro Faccenda
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
php5 (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Thats a security issue found on MySQL clients which also affects the PHP MySQL native driver.

It was already fixed on PHP sources: https://bugs.php.net/bug.php?id=69669

Description:
------------
mysqlnd is vulnerable to the attack described in https://www.duosecurity.com/blog/backronym-mysql-vulnerability

mysqlnd allows downgrade to non-SSL connection even if SSL was requested.

Expected result:
----------------
Fail to connect if SSL is requested but not provided as capability by the server.

Actual result:
--------------
mysqlnd allows downgrade to non-SSL connection even if SSL was requested.

However, the fix was not backported to Ubuntu's PHP packages.

Before opening this bug I was trying to figure out why it didn't happen and I made the question on the following link, which gives more details:

https://answers.launchpad.net/ubuntu/+source/php5/+question/289607

CVE References

information type: Private Security → Public Security
Revision history for this message
Seth Arnold (seth-arnold) wrote :

I've asked MITRE if this needs a new CVE or not:

http://www.openwall.com/lists/oss-security/2016/03/31/10

Thanks

Revision history for this message
Seth Arnold (seth-arnold) wrote :
summary: - mysqlnd is vulnerable to BACKRONYM (CVE-2015-3152)
+ mysqlnd is vulnerable to BACKRONYM (CVE-2015-8838)
Changed in php5 (Ubuntu):
status: New → Confirmed
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :
Changed in php5 (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.