7.5
CVSSv2

CVE-2008-0227

Published: 10/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 830
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

yaSSL 1.7.5 and previous versions, as used in MySQL and possibly other products, allows remote malicious users to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

Vulnerable Product Search on Vulmon Subscribe to Product

yassl yassl

Vendor Advisories

Luigi Auriemma discovered two buffer overflows in YaSSL, an SSL implementation included in the MySQL database package, which could lead to denial of service and possibly the execution of arbitrary code The old stable distribution (sarge) doesn't contain mysql-dfsg-50 For the stable distribution (etch), these problems have been fixed in version 5 ...
USN-588-1 fixed vulnerabilities in MySQL In fixing CVE-2007-2692 for Ubuntu 606, additional improvements were made to make privilege checks more restictive As a result, an upstream bug was exposed which could cause operations on tables or views in a different database to fail This update fixes the problem ...
Masaaki Hirose discovered that MySQL could be made to dereference a NULL pointer An authenticated user could cause a denial of service (application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table This issue only affects Ubuntu 606 and 610 (CVE-2006-7232) ...