Red Hat released updated MariaDB packages for Red Hat Enterprise Linux 7 and Red Hat Software Collections 2 to remediate CVE-2015-3152, a man-in-the-middle vulnerability in which MySQL client connections using --ssl could be downgraded or stripped of SSL/TLS protection. The flaw affected MariaDB 5.5 and 10.0 package streams and could expose database traffic to interception when clients did not require encrypted transport.
The updates deliver MariaDB 5.5.44 through the mariadb55-mariadb and RHEL 7 packages, and MariaDB 10.0.20 through rh-mariadb100-mariadb. They also address 15 additional MariaDB/MySQL server vulnerabilities in the 5.5 updates and 18 additional vulnerabilities in the 10.0 update, based on Oracle's Critical Patch Update advisory. Red Hat rated the 5.5 updates Moderate and the 10.0 update Important, advised affected users to install the packages, and noted that installation automatically restarts mysqld.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released a Moderate-security MariaDB update for Red Hat Enterprise Linux 7, upgrading the software to version 5.5.44. It fixed CVE-2015-3152 and 15 additional MariaDB/MySQL server vulnerabilities; mysqld restarts automatically after installation.
Red Hat released a Moderate-security mariadb55-mariadb update for Red Hat Software Collections 2, upgrading MariaDB to 5.5.44. The update remediated CVE-2015-3152, which could allow a man-in-the-middle attacker to strip SSL/TLS from --ssl MySQL client connections, plus 15 other vulnerabilities.
Red Hat released an Important-security update for rh-mariadb100-mariadb in Red Hat Software Collections 2, upgrading MariaDB to 10.0.20. It fixed CVE-2015-3152 and 18 additional MariaDB/MySQL server vulnerabilities; installing it restarts mysqld automatically.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.