PublicDateAtUSN: 2015-12-31 Candidate: CVE-2015-8838 PublicDate: 2016-05-16 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8838 https://ubuntu.com/security/notices/USN-2952-1 Description: ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1564388 https://bugs.php.net/bug.php?id=69669 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N [5.9 MEDIUM] Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commit;h=0d2f147d80bd02d4d1ccaa0fa530d9d4846b3c75 upstream_php5: released (5.6.11+dfsg-1) precise_php5: released (5.3.10-1ubuntu3.22) trusty_php5: released (5.5.9+dfsg-1ubuntu4.16) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.16) vivid/stable-phone-overlay_php5: DNE vivid/ubuntu-core_php5: DNE wily_php5: not-affected (5.6.11+dfsg-1ubuntu3.1) devel_php5: DNE Patches_php7.0: upstream_php7.0: released (7.0.0) precise_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/stable-phone-overlay_php7.0: DNE vivid/ubuntu-core_php7.0: DNE wily_php7.0: DNE devel_php7.0: not-affected (7.0.4-5ubuntu2)