CVE-2015-8838

Published: 31 December 2015

ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.

Priority

Medium

CVSS 3 base score: 5.9

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
Upstream
Released (5.6.11+dfsg-1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (5.5.9+dfsg-1ubuntu4.16)
Patches:
Upstream: http://git.php.net/?p=php-src.git;a=commit;h=0d2f147d80bd02d4d1ccaa0fa530d9d4846b3c75
php7.0
Launchpad, Ubuntu, Debian
Upstream
Released (7.0.0)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist