yaSSL Multiple Remote Buffer Overflow Vulnerabilities
BID:27140
Info
yaSSL Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 27140 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0226 CVE-2008-0227 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2008 12:00AM |
| Updated: | Jan 28 2010 05:21AM |
| Credit: | Luigi Auriemma discovered these vulnerabilities. |
| Vulnerable: |
yaSSL yaSSL 1.7.5 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Apple Mac OS X Server 10.5.5 |
| Not Vulnerable: | |
Discussion
yaSSL Multiple Remote Buffer Overflow Vulnerabilities
yaSSL is prone to multiple remote buffer-overflow vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the library. Failed attacks will cause denial-of-service conditions.
yaSSL 1.7.5 is vulnerable to these issues; other versions are also likely to be affected.
yaSSL is prone to multiple remote buffer-overflow vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the library. Failed attacks will cause denial-of-service conditions.
yaSSL 1.7.5 is vulnerable to these issues; other versions are also likely to be affected.
Exploit / POC
Solution / Fix
yaSSL Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
Apple Mac OS X Server 10.5.5
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
Apple Mac OS X Server 10.5.5
-
Apple SecUpdSrvr2008-007.dmg
http://www.apple.com/support/downloads/securityupdate2008007serverleop ard.html
References
yaSSL Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- yaSSL Homepage (yaSSL)
- Multiple vulnerabilities in yaSSL 1.7.5 (Luigi Auriemma
) - Pre-auth buffer-overflow in mySQL through yaSSL (Luigi Auriemma
)