UBUNTU-CVE-2017-10789
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-10789
UBUNTU-CVE-2017-10789
Summary:
Details: The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
References: https://ubuntu.com/security/CVE-2017-10789, https://github.com/perl5-dbi/DBD-mysql/pull/114, https://ubuntu.com/security/notices/USN-5344-1, https://www.cve.org/CVERecord?id=CVE-2017-10789, https://ubuntu.com/security/notices/USN-7417-1
Affected packages
Package
Name: libdbd-mysql-perl
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
