CVE-2009-4484
30.12.2009, 21:30
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oracle | mysql | 5.0.0 ≤ 𝑥 < 5.0.90 |
| oracle | mysql | 5.1.0 ≤ 𝑥 < 5.1.43 |
| oracle | mysql | 5.0.0:milestone1 |
| oracle | mysql | 5.0.0:milestone2 |
| wolfssl | yassl | 𝑥 < 1.9.9 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 8.10 |
| canonical | ubuntu_linux | 9.04 |
| canonical | ubuntu_linux | 9.10 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 10.10 |
| canonical | ubuntu_linux | 11.04 |
| canonical | ubuntu_linux | 11.10 |
| debian | debian_linux | 4.0 |
| debian | debian_linux | 5.0 |
| debian | debian_linux | 6.0 |
| mariadb | mariadb | 5.1 ≤ 𝑥 < 5.1.42 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mysql-5.1 |
| ||||||||||||||||
| mysql-dfsg-5.0 |
| ||||||||||||||||
| mysql-dfsg-5.1 |
|
Common Weakness Enumeration
References