Your submission was sent successfully! Close

CVE-2015-8838

Published: 31 December 2015

ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.

Priority

Medium

CVSS 3 base score: 5.9

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
precise
Released (5.3.10-1ubuntu3.22)
trusty
Released (5.5.9+dfsg-1ubuntu4.16)
upstream
Released (5.6.11+dfsg-1)
wily Not vulnerable
(5.6.11+dfsg-1ubuntu3.1)
Patches:
upstream: http://git.php.net/?p=php-src.git;a=commit;h=0d2f147d80bd02d4d1ccaa0fa530d9d4846b3c75
php7.0
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist

upstream
Released (7.0.0)
wily Does not exist