Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Dec 30, 2009 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Dec 30, 2009 |
| Suse | — | Upgrade libmysql55client18Upgrade libmysqlclient_r15Upgrade libmysqlclient_r15-x86Upgrade libmysqlclient_r15-32bitUpgrade libmysql55client_r18Upgrade mysql-MaxUpgrade libmysql55client_r18-32bitUpgrade libmysqlclient15Upgrade libmysql55client_r18-x86Upgrade libmysql55client18-32bitUpgrade mysql-toolsUpgrade libmysqlclient15-32bitUpgrade libmysql55client18-x86Upgrade mysql-clientUpgrade mysqlUpgrade libmysqlclient15-x86Upgrade libmysqlclient-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.0Upgrade mysql-server-5.1 | Nov 8, 2024 | Dec 30, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub