Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2009-4484 Details

Description

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://archives.neohapsis.com/archives/dailydave/2010-q1/0002.html CVEBroken Link
http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1 CVEBroken Link
http://bugs.mysql.com/bug.php?id=50227 CVEExploitIssue TrackingVendor Advisory
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html CVEBroken Link
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html CVEBroken Link

see all 72 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-787Out-of-bounds Write[email protected]

Affected Products

ProductVersions
oracle mysql
>= 5.0.0, < 5.0.90
>= 5.1.0, < 5.1.43
5.0.0 milestone1
5.0.0 milestone2

CPE

  • cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:mysql:5.0.0:milestone1:*:*:*:*:*:*
  • cpe:2.3:a:oracle:mysql:5.0.0:milestone2:*:*:*:*:*:*

Remediation

  • No remediation found in references.
wolfssl yassl
< 1.9.9

CPE

  • cpe:2.3:a:wolfssl:yassl:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
canonical ubuntu linux
6.06
8.04
8.10
9.04
9.10

CPE

  • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
4.0
5.0
6.0

CPE

  • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
mariadb mariadb
>= 5.1, < 5.1.42

CPE

  • cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2009-4484
NVD Published Date:
Dec 30, 2009
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2009-4484 Details - Not Deferred