Uploaded image for project: 'MariaDB Connector/C'
  1. MariaDB Connector/C
  2. CONC-846

Auth-switch allows cleartext password leakage on TLS hostname verification failure

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Critical
    • Resolution: Fixed
    • 3.4.9
    • 3.4.10
    • Authentication
    • None

    Description

      A logic flaw in run_plugin_auth() (plugins/auth/my_auth.c) allows a Man-in-the-Middle (MITM) attacker to capture a client's plaintext database password during TLS-secured authentication.

      When a TLS certificate's CA is trusted but the hostname mismatches, ma_verification_callback() sets:
      mysql->net.tls_verify_status = MARIADB_TLS_VERIFY_HOST (value 2).

      The guard in run_plugin_auth() previously checked:

       
      if ((mysql->net.tls_verify_status & MARIADB_TLS_VERIFY_TRUST) &&
          !password_and_hashing(mysql, auth_plugin))
      

      Because MARIADB_TLS_VERIFY_TRUST is bit 1, (2 & 1) evaluated to 0, bypassing the guard. An attacker acting as a MITM proxy can request an auth-switch (0xFE) to mysql_clear_password, causing the client to transmit plaintext credentials over the TLS tunnel prior to connection termination.

      originally reported by AISLE research

      Attachments

        Issue Links

          Activity

            People

              georg Georg Richter
              georg Georg Richter
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.