SB2016042701 - Spoofing attack in MySQL 



SB2016042701 - Spoofing attack in MySQL

Published: April 27, 2016 Updated: June 28, 2016

Security Bulletin ID SB2016042701
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Spoofing attack (CVE-ID: CVE-2016-2047)

The vulnerability allows a remote attacker to gain to perform a MitM attack.

The vulnerability exists due to improper validation of server hostname in Common Name (CN) or subjectAltName field of X.509 certificate in ssl_verify_server_cert() function in sql-common/client.c. A remote attacker can create a specially crafted certificate and spoof SSL server via multiple CN strings within one filed, e.g. "/OU=/CN=bar.com/CN=foo.com".

Successful exploitation of this vulnerability may allow an attacker to perform Man-in-the-Middle (MitM) attack and intercept SSL traffic and perform spoofing attack.


Remediation

Install update from vendor's website.