Details
-
Bug
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Fixed
-
3.4.9
-
None
Description
A logic flaw in run_plugin_auth() (plugins/auth/my_auth.c) allows a Man-in-the-Middle (MITM) attacker to capture a client's plaintext database password during TLS-secured authentication.
When a TLS certificate's CA is trusted but the hostname mismatches, ma_verification_callback() sets:
mysql->net.tls_verify_status = MARIADB_TLS_VERIFY_HOST (value 2).
The guard in run_plugin_auth() previously checked:
 |
if ((mysql->net.tls_verify_status & MARIADB_TLS_VERIFY_TRUST) && |
!password_and_hashing(mysql, auth_plugin))
|
Because MARIADB_TLS_VERIFY_TRUST is bit 1, (2 & 1) evaluated to 0, bypassing the guard. An attacker acting as a MITM proxy can request an auth-switch (0xFE) to mysql_clear_password, causing the client to transmit plaintext credentials over the TLS tunnel prior to connection termination.
originally reported by AISLE research
Attachments
Issue Links
- causes
-
CONC-854 CONC-846 breaks connections by IP address when ssl_ca is set (disable-ssl-verify-server-cert silently ignored)
-
- Open
-