Medium severity5.9NVD Advisory· Published Jul 1, 2017· Updated May 13, 2026
CVE-2017-10789
CVE-2017-10789
Description
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/99364nvdThird Party AdvisoryVDB Entry
- github.com/perl5-dbi/DBD-mysql/issues/110nvdThird Party Advisory
- github.com/perl5-dbi/DBD-mysql/pull/114nvdThird Party Advisory
- github.com/perl5-dbi/DBD-mysql/issues/140nvd
News mentions
0No linked articles in our index yet.