Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4484

Опубликовано: 30 дек. 2009
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 7.5

Описание

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

РелизСтатусПримечание
dapper

DNE

devel

released

5.1.41-3ubuntu7
hardy

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

released

5.1.41-3ubuntu7
natty

released

5.1.41-3ubuntu7
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

5.0.22-0ubuntu6.06.12
devel

DNE

hardy

released

5.0.51a-3ubuntu5.5
intrepid

released

5.0.67-0ubuntu6.1
jaunty

released

5.1.30really5.0.75-0ubuntu10.3
karmic

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

ignored

end of life
karmic

released

5.1.37-1ubuntu5.1
lucid

released

5.1.41-3ubuntu7
maverick

DNE

natty

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 99%
0.72085
Высокий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

nvd
больше 15 лет назад

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

msrc
больше 4 лет назад

Описание отсутствует

debian
больше 15 лет назад

Multiple stack-based buffer overflows in the CertDecoder::GetName func ...

github
около 3 лет назад

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

EPSS

Процентиль: 99%
0.72085
Высокий

7.5 High

CVSS2