CVE-2015-8838
Summary
| CVE | CVE-2015-8838 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-05-16 10:59:00 UTC |
| Updated | 2023-11-07 02:28:00 UTC |
| Description | ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Php |
Php |
5.5.0 |
All |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha2 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha3 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha4 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha5 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha6 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
rc1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
rc2 |
All |
All |
| Application |
Php |
Php |
5.5.1 |
All |
All |
All |
| Application |
Php |
Php |
5.5.10 |
All |
All |
All |
| Application |
Php |
Php |
5.5.11 |
All |
All |
All |
| Application |
Php |
Php |
5.5.12 |
All |
All |
All |
| Application |
Php |
Php |
5.5.13 |
All |
All |
All |
| Application |
Php |
Php |
5.5.14 |
All |
All |
All |
| Application |
Php |
Php |
5.5.15 |
All |
All |
All |
| Application |
Php |
Php |
5.5.16 |
All |
All |
All |
| Application |
Php |
Php |
5.5.17 |
All |
All |
All |
| Application |
Php |
Php |
5.5.18 |
All |
All |
All |
| Application |
Php |
Php |
5.5.19 |
All |
All |
All |
| Application |
Php |
Php |
5.5.2 |
All |
All |
All |
| Application |
Php |
Php |
5.5.20 |
All |
All |
All |
| Application |
Php |
Php |
5.5.21 |
All |
All |
All |
| Application |
Php |
Php |
5.5.22 |
All |
All |
All |
| Application |
Php |
Php |
5.5.23 |
All |
All |
All |
| Application |
Php |
Php |
5.5.24 |
All |
All |
All |
| Application |
Php |
Php |
5.5.25 |
All |
All |
All |
| Application |
Php |
Php |
5.5.26 |
All |
All |
All |
| Application |
Php |
Php |
5.5.3 |
All |
All |
All |
| Application |
Php |
Php |
5.5.4 |
All |
All |
All |
| Application |
Php |
Php |
5.5.5 |
All |
All |
All |
| Application |
Php |
Php |
5.5.6 |
All |
All |
All |
| Application |
Php |
Php |
5.5.7 |
All |
All |
All |
| Application |
Php |
Php |
5.5.8 |
All |
All |
All |
| Application |
Php |
Php |
5.5.9 |
All |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha1 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha2 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha3 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha4 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha5 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.6.1 |
All |
All |
All |
| Application |
Php |
Php |
5.6.10 |
All |
All |
All |
| Application |
Php |
Php |
5.6.2 |
All |
All |
All |
| Application |
Php |
Php |
5.6.3 |
All |
All |
All |
| Application |
Php |
Php |
5.6.4 |
All |
All |
All |
| Application |
Php |
Php |
5.6.5 |
All |
All |
All |
| Application |
Php |
Php |
5.6.6 |
All |
All |
All |
| Application |
Php |
Php |
5.6.7 |
All |
All |
All |
| Application |
Php |
Php |
5.6.8 |
All |
All |
All |
| Application |
Php |
Php |
5.6.9 |
All |
All |
All |
| Application |
Php |
Php |
5.5.0 |
All |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha2 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha3 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha4 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha5 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
alpha6 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
rc1 |
All |
All |
| Application |
Php |
Php |
5.5.0 |
rc2 |
All |
All |
| Application |
Php |
Php |
5.5.1 |
All |
All |
All |
| Application |
Php |
Php |
5.5.10 |
All |
All |
All |
| Application |
Php |
Php |
5.5.11 |
All |
All |
All |
| Application |
Php |
Php |
5.5.12 |
All |
All |
All |
| Application |
Php |
Php |
5.5.13 |
All |
All |
All |
| Application |
Php |
Php |
5.5.14 |
All |
All |
All |
| Application |
Php |
Php |
5.5.15 |
All |
All |
All |
| Application |
Php |
Php |
5.5.16 |
All |
All |
All |
| Application |
Php |
Php |
5.5.17 |
All |
All |
All |
| Application |
Php |
Php |
5.5.18 |
All |
All |
All |
| Application |
Php |
Php |
5.5.19 |
All |
All |
All |
| Application |
Php |
Php |
5.5.2 |
All |
All |
All |
| Application |
Php |
Php |
5.5.20 |
All |
All |
All |
| Application |
Php |
Php |
5.5.21 |
All |
All |
All |
| Application |
Php |
Php |
5.5.22 |
All |
All |
All |
| Application |
Php |
Php |
5.5.23 |
All |
All |
All |
| Application |
Php |
Php |
5.5.24 |
All |
All |
All |
| Application |
Php |
Php |
5.5.25 |
All |
All |
All |
| Application |
Php |
Php |
5.5.26 |
All |
All |
All |
| Application |
Php |
Php |
5.5.3 |
All |
All |
All |
| Application |
Php |
Php |
5.5.4 |
All |
All |
All |
| Application |
Php |
Php |
5.5.5 |
All |
All |
All |
| Application |
Php |
Php |
5.5.6 |
All |
All |
All |
| Application |
Php |
Php |
5.5.7 |
All |
All |
All |
| Application |
Php |
Php |
5.5.8 |
All |
All |
All |
| Application |
Php |
Php |
5.5.9 |
All |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha1 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha2 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha3 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha4 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
alpha5 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.6.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.6.1 |
All |
All |
All |
| Application |
Php |
Php |
5.6.10 |
All |
All |
All |
| Application |
Php |
Php |
5.6.2 |
All |
All |
All |
| Application |
Php |
Php |
5.6.3 |
All |
All |
All |
| Application |
Php |
Php |
5.6.4 |
All |
All |
All |
| Application |
Php |
Php |
5.6.5 |
All |
All |
All |
| Application |
Php |
Php |
5.6.6 |
All |
All |
All |
| Application |
Php |
Php |
5.6.7 |
All |
All |
All |
| Application |
Php |
Php |
5.6.8 |
All |
All |
All |
| Application |
Php |
Php |
5.6.9 |
All |
All |
All |
| Application |
Php |
Php |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] SUSE-SU-2016:1145-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| USN-2952-2: PHP regression | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| PHP :: Sec Bug #69669 :: mysqlnd is vulnerable to BACKRONYM (CVE-2015-3152) |
CONFIRM |
bugs.php.net |
|
| [security-announce] SUSE-SU-2016:1166-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| 208.43.231.11 Git - php-src.git/commit |
|
git.php.net |
|
| USN-2952-1: PHP vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] openSUSE-SU-2016:1173-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| PHP: PHP 5 ChangeLog |
CONFIRM |
php.net |
|
| 208.43.231.11 Git - php-src.git/commit |
CONFIRM |
git.php.net |
|
| [security-announce] openSUSE-SU-2016:1167-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 670246 EulerOS Security Update for php (EulerOS-SA-2021-1830)