CVE Database
/

CVE-2009-4484

Back to search

CVE-2009-4484

Published: Dec 30, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

VendorProductVersions

n/a

n/a

affected
n/a

References

38573
third-party-advisory
x_refsource_SECUNIA
USN-1397-1
vendor-advisory
x_refsource_UBUNTU
37493
third-party-advisory
x_refsource_SECUNIA
38364
third-party-advisory
x_refsource_SECUNIA
38517
third-party-advisory
x_refsource_SECUNIA
37974
vdb-entry
x_refsource_BID
1023513
vdb-entry
x_refsource_SECTRACK
USN-897-1
vendor-advisory
x_refsource_UBUNTU
ADV-2010-0236
vdb-entry
x_refsource_VUPEN
[dailydave] 20100106 0day demos
mailing-list
x_refsource_MLIST
37640
vdb-entry
x_refsource_BID
mysql-unspecified-bo(55416)
vdb-entry
x_refsource_XF
1023402
vdb-entry
x_refsource_SECTRACK
61956
vdb-entry
x_refsource_OSVDB
38344
third-party-advisory
x_refsource_SECUNIA
37943
vdb-entry
x_refsource_BID
ADV-2010-0233
vdb-entry
x_refsource_VUPEN
[dailydave] 20100126 New db bugs
mailing-list
x_refsource_MLIST
DSA-1997
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now