CVE-2009-4484
Summary
| CVE | CVE-2009-4484 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-30 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-897-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| RETIRED: yaSSL SSL Certificate Handling Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Metasploit Penetration Testing Framework - Module Browser | af854a3a-2127-422b-91ae-364da2661108 | www.metasploit.com | Third Party Advisory |
| MySQL Lists: commits: bzr commit into mysql-5.0-bugteam branch (ramil:2838) Bug#50227 | af854a3a-2127-422b-91ae-364da2661108 | lists.mysql.com | Patch, Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | intevydis.com | Broken Link |
| yaSSL | Release notes | af854a3a-2127-422b-91ae-364da2661108 | www.yassl.com | Broken Link |
| www.intevydis.com/blog | af854a3a-2127-422b-91ae-364da2661108 | www.intevydis.com | Broken Link |
| Bug 555313 – CVE-2009-4484 mysql: yaSSL certificate parsing buffer overflow (vulndisco) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| lists.immunitysec.com/pipermail/dailydave/2010-January/006020.html | af854a3a-2127-422b-91ae-364da2661108 | lists.immunitysec.com | Broken Link |
| yaSSL Buffer Overflow in Certificate Processing Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| MySQL with yaSSL SSL Certificate Handling Remote Stack Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Broken Link |
| MySQL 5.0.51a Unspecified Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Intevydis blog: MySQL yassl stack overflow | af854a3a-2127-422b-91ae-364da2661108 | intevydis.blogspot.com | Broken Link |
| MySQL Bugs: Access denied | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | Exploit, Issue Tracking, Vendor Advisory |
| MySQL :: MySQL 5.1 Reference Manual :: C.1.1 Changes in MySQL 5.1.43 (Not yet released) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| MySQL :: MySQL 5.0 Reference Manual :: C.1.1 Changes in MySQL 5.0.90 (15 January 2010) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | Broken Link |
| MySQL remote exploit demo | af854a3a-2127-422b-91ae-364da2661108 | intevydis.com | Broken Link |
| Not Found | af854a3a-2127-422b-91ae-364da2661108 | bazaar.launchpad.net | Broken Link |
| www.osvdb.org/61956 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| MySQL Unspecified Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| yaSSL | News Security Library | af854a3a-2127-422b-91ae-364da2661108 | www.yassl.com | Broken Link |
| VulnDisco Pack Professional 8.11 « Intevydis blog | af854a3a-2127-422b-91ae-364da2661108 | www.intevydis.com | Broken Link |
| Possible new MySQL 0day | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Ubuntu update for mysql-dfsg-5 and mysql-dfsg-5.1 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| USN-1397-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Debian update for mysql-dfsg-5.0 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | intevydis.com | Broken Link |
| yaSSL Certificate Processing Buffer Overflow Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| CVS Info for project yassl | af854a3a-2127-422b-91ae-364da2661108 | yassl.cvs.sourceforge.net | Third Party Advisory |
| MySQL yaSSL Certificate Processing Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1997-1 mysql-dfsg-5.0 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| yaSSL Certificate Processing Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-01-26 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3, 4, or 5. The packages use OpenSSL and not yaSSL. |