7.5

CVE-2008-0226

Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.

Data is provided by the National Vulnerability Database (NVD)
YasslYassl Version <= 1.7.5
MysqlMysql Version5.0.0
MysqlMysql Version5.0.1
MysqlMysql Version5.0.2
MysqlMysql Version5.0.3
MysqlMysql Version5.0.4
MysqlMysql Version5.0.5
MysqlMysql Version5.0.10
MysqlMysql Version5.0.15
MysqlMysql Version5.0.16
MysqlMysql Version5.0.17
MysqlMysql Version5.0.20
MysqlMysql Version5.0.24
MysqlMysql Version5.0.30
MysqlMysql Version5.0.36
MysqlMysql Version5.0.44
MysqlMysql Version5.0.54
MysqlMysql Version5.0.56
MysqlMysql Version5.0.60
MysqlMysql Version5.0.66
MysqlMysql Version5.1.5
OracleMysql Version5.0.23
OracleMysql Version5.0.25
OracleMysql Version5.0.26
OracleMysql Version5.0.28
OracleMysql Version5.0.30 Updatesp1
OracleMysql Version5.0.32
OracleMysql Version5.0.34
OracleMysql Version5.0.36 Updatesp1
OracleMysql Version5.0.38
OracleMysql Version5.0.40
OracleMysql Version5.0.41
OracleMysql Version5.0.42
OracleMysql Version5.0.44 Updatesp1
OracleMysql Version5.0.45
OracleMysql Version5.0.46
OracleMysql Version5.0.48
OracleMysql Version5.0.50
OracleMysql Version5.0.50 Updatesp1
OracleMysql Version5.0.51
OracleMysql Version5.0.52
OracleMysql Version5.0.56 Updatesp1
OracleMysql Version5.0.58
OracleMysql Version5.0.60 Updatesp1
OracleMysql Version5.0.62
OracleMysql Version5.0.64
OracleMysql Version5.0.66 Updatesp1
OracleMysql Version5.1
OracleMysql Version5.1.1
OracleMysql Version5.1.2
OracleMysql Version5.1.3
OracleMysql Version5.1.4
OracleMysql Version5.1.6
OracleMysql Version5.1.7
OracleMysql Version5.1.8
OracleMysql Version5.1.9
OracleMysql Version5.1.10
OracleMysql Version5.1.11
OracleMysql Version5.1.12
OracleMysql Version5.1.13
OracleMysql Version5.1.14
OracleMysql Version5.1.15
OracleMysql Version5.1.16
OracleMysql Version5.1.17
OracleMysql Version5.1.18
OracleMysql Version5.1.19
OracleMysql Version5.1.20
OracleMysql Version5.1.21
OracleMysql Version5.1.22
ApplemacOS X Version10.5.4
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.94% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/31681
Third Party Advisory
VDB Entry
http://bugs.mysql.com/33814
Permissions Required
http://www.securityfocus.com/bid/27140
Third Party Advisory
VDB Entry