First published: Wed Dec 30 2009(Updated: )
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL | =5.0.0-milestone2 | |
Oracle MySQL | =5.0.0-milestone1 | |
Oracle MySQL | >=5.1.0<5.1.43 | |
Oracle MySQL | >=5.0.0<5.0.90 | |
Wolfssl Yassl | <1.9.9 | |
Canonical Ubuntu Linux | =10.10 | |
Canonical Ubuntu Linux | =11.04 | |
Canonical Ubuntu Linux | =11.10 | |
Canonical Ubuntu Linux | =9.04 | |
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =9.10 | |
Canonical Ubuntu Linux | =8.04 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =6.06 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =4.0 | |
Debian Debian Linux | =6.0 | |
Mariadb Mariadb | >=5.1<5.1.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.