Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4028

Опубликовано: 30 нояб. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

5.0.22-0ubuntu6.06.11
devel

not-affected

5.1.30really5.0.83-0ubuntu3
hardy

not-affected

5.0.51a-3ubuntu5.4
intrepid

not-affected

5.0.67-0ubuntu6
jaunty

not-affected

5.1.30really5.0.75-0ubuntu10.2
karmic

not-affected

5.1.30really5.0.83-0ubuntu3
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

5.1.41-3ubuntu2
hardy

DNE

intrepid

DNE

jaunty

not-affected

5.1.31-1ubuntu2
karmic

not-affected

5.1.37-1ubuntu5
upstream

needs-triage

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

nvd
больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

debian
больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x b ...

github
около 3 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

oracle-oval
больше 15 лет назад

ELSA-2010-0109: mysql security update (MODERATE)

6.8 Medium

CVSS2

Уязвимость CVE-2009-4028