Vulnerability Name: | CCN-55877 | ||||||
Published: | 2010-01-25 | ||||||
Updated: | 2010-01-25 | ||||||
Summary: | MySQL, when running with SSL support, is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when parsing certificates by the yaSSL library. By sending a specially-crafted SSL certificate, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application using the vulnerable library to crash. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: MySQL Web site MySQL Downloads Source: CCN Type: Intevydis blog MySQL yassl stack overflow Source: CCN Type: SA37493 yaSSL Certificate Processing Buffer Overflow Vulnerability Source: CCN Type: SA38344 yaSSL Certificate Processing Buffer Overflow Vulnerability Source: CCN Type: SA38364 MySQL yaSSL Certificate Processing Buffer Overflow Vulnerability Source: CCN Type: Packetstorm Security Web Site This Metasploit module exploits a stack overflow in the yaSSL (1.7.5 and earlier) implementation bundled with MySQL <= 6.0. By sending a specially crafted Hello packet, an attacker may be able to execute arbitrary code Source: CCN Type: BID-37943 MySQL with yaSSL SSL Certificate Handling Remote Stack Buffer Overflow Vulnerability Source: CCN Type: yaSSL Web Site yaSSL Release notes, version 1.9.9 Source: XF Type: UNKNOWN mysql-yassl-bo(55877) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |