First published: Wed Dec 30 2009(Updated: )
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=5.0.0<5.0.90 | |
MySQL | >=5.1.0<5.1.43 | |
MySQL | =5.0.0-milestone1 | |
MySQL | =5.0.0-milestone2 | |
wolfSSL | <1.9.9 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =8.04 | |
Ubuntu Linux | =8.10 | |
Ubuntu Linux | =9.04 | |
Ubuntu Linux | =9.10 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =10.10 | |
Ubuntu Linux | =11.04 | |
Ubuntu Linux | =11.10 | |
Debian GNU/Linux | =4.0 | |
Debian GNU/Linux | =5.0 | |
Debian GNU/Linux | =6.0 | |
Ariadne CMS | >=5.1<5.1.42 | |
Ubuntu | =10.10 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =9.04 | |
Ubuntu | =8.10 | |
Ubuntu | =9.10 | |
Ubuntu | =8.04 | |
Ubuntu | =10.04 | |
Ubuntu | =6.06 | |
Debian | =5.0 | |
Debian | =4.0 | |
Debian | =6.0 | |
MariaDB | >=5.1<5.1.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4484 is rated as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2009-4484, you should update to the latest version of MySQL or yajSSL that addresses the buffer overflow issue.
CVE-2009-4484 affects MySQL versions 5.0.x before 5.0.90, 5.1.x before 5.1.43, and 5.5.x through 5.5.0-m2.
If you are using an affected version of MySQL or libraries on Debian, your system could be vulnerable to CVE-2009-4484.
CVE-2009-4484 is classified as a stack-based buffer overflow vulnerability.