CVE-2009-4484

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 30 Dec 2009, 21:00
Last modified:07 Aug 2024, 07:01

Vulnerability Summary

Overall Risk (default)
high
55/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
75.82% CRITICAL
76% probability +1.21%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

30 Dec 2009, 21:00
Published
Vulnerability first disclosed
07 Aug 2024, 07:01
Last Modified
Vulnerability information updated

Description

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 75.82% Percentile: 99%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 8.10 | 9.04 | 9.10 | 10.04 | 10.10 | 11.04 | 11.10

  • debiandebian_linux

    4.0 | 5.0 | 6.0

  • mariadbmariadb

    ≥ 5.1, < 5.1.42

  • oraclemysql

    ≥ 5.0.0, < 5.0.90 | ≥ 5.1.0, < 5.1.43 | 5.0.0:milestone1 | 5.0.0:milestone2

  • wolfsslyassl

    < 1.9.9

References (36)