Man-in-the-middle attack in MySQL Server - CVE-2018-2767
Published: June 8, 2018 / Updated: June 8, 2018
Vulnerability identifier: #VU13235
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-2767
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.
The vulnerability exists due to presence of BACKRONYM vulnerability. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the victim and affected app, bypass security restrictions and downgrade and snoop on the SSL/TLS connection.
Affected software
MySQL Server
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Fedora
mariadb (Alpine package)
openSUSE Leap
mariadb
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Fedora
mariadb (Alpine package)
openSUSE Leap
mariadb
How to mitigate CVE-2018-2767
Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.
mariadb (Alpine package) - update to 10.1.37-r0
mariadb - addressed in versions 10.2.17-1.fc27, 10.2.17-1.fc28
mariadb - addressed in versions 10.2.17-1.fc27, 10.2.17-1.fc28