6.8

CVE-2009-4028

Exploit

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

Data is provided by the National Vulnerability Database (NVD)
MysqlMysql Version <= 5.0.87
MysqlMysql Version5.0.0
MysqlMysql Version5.0.1
MysqlMysql Version5.0.2
MysqlMysql Version5.0.3
MysqlMysql Version5.0.4
MysqlMysql Version5.0.5
MysqlMysql Version5.0.5.0.21
MysqlMysql Version5.0.10
MysqlMysql Version5.0.15
MysqlMysql Version5.0.16
MysqlMysql Version5.0.17
MysqlMysql Version5.0.20
MysqlMysql Version5.0.22.1.0.1
MysqlMysql Version5.0.24
MysqlMysql Version5.0.30
MysqlMysql Version5.0.36
MysqlMysql Version5.0.44
MysqlMysql Version5.0.54
MysqlMysql Version5.0.56
MysqlMysql Version5.0.60
MysqlMysql Version5.0.66
MysqlMysql Version5.0.82
MysqlMysql Version5.0.84
MysqlMysql Version5.1.5
MysqlMysql Version5.1.23
MysqlMysql Version5.1.31
MysqlMysql Version5.1.32
MysqlMysql Version5.1.34
MysqlMysql Version5.1.37
OracleMysql Version5.0.0 Updatealpha
OracleMysql Version5.0.3 Updatebeta
OracleMysql Version5.0.6
OracleMysql Version5.0.7
OracleMysql Version5.0.8
OracleMysql Version5.0.11
OracleMysql Version5.0.12
OracleMysql Version5.0.13
OracleMysql Version5.0.14
OracleMysql Version5.0.18
OracleMysql Version5.0.19
OracleMysql Version5.0.21
OracleMysql Version5.0.22
OracleMysql Version5.0.23
OracleMysql Version5.0.25
OracleMysql Version5.0.26
OracleMysql Version5.0.27
OracleMysql Version5.0.30 Updatesp1
OracleMysql Version5.0.32
OracleMysql Version5.0.33
OracleMysql Version5.0.37
OracleMysql Version5.0.38
OracleMysql Version5.0.41
OracleMysql Version5.0.42
OracleMysql Version5.0.45
OracleMysql Version5.0.50
OracleMysql Version5.0.51
OracleMysql Version5.0.52
OracleMysql Version5.0.75
OracleMysql Version5.0.77
OracleMysql Version5.0.81
OracleMysql Version5.0.83
OracleMysql Version5.0.85
OracleMysql Version5.0.86
OracleMysql Version5.1
OracleMysql Version5.1.1
OracleMysql Version5.1.2
OracleMysql Version5.1.3
OracleMysql Version5.1.4
OracleMysql Version5.1.6
OracleMysql Version5.1.7
OracleMysql Version5.1.8
OracleMysql Version5.1.9
OracleMysql Version5.1.10
OracleMysql Version5.1.11
OracleMysql Version5.1.12
OracleMysql Version5.1.13
OracleMysql Version5.1.14
OracleMysql Version5.1.15
OracleMysql Version5.1.16
OracleMysql Version5.1.17
OracleMysql Version5.1.18
OracleMysql Version5.1.19
OracleMysql Version5.1.20
OracleMysql Version5.1.21
OracleMysql Version5.1.22
OracleMysql Version5.1.23 Updatea
OracleMysql Version5.1.24
OracleMysql Version5.1.25
OracleMysql Version5.1.26
OracleMysql Version5.1.27
OracleMysql Version5.1.28
OracleMysql Version5.1.29
OracleMysql Version5.1.30
OracleMysql Version5.1.31 Updatesp1
OracleMysql Version5.1.33
OracleMysql Version5.1.34 Updatesp1
OracleMysql Version5.1.35
OracleMysql Version5.1.36
OracleMysql Version5.1.37 Updatesp1
OracleMysql Version5.1.38
OracleMysql Version5.1.39
OracleMysql Version5.1.40
OracleMysql Version5.1.40 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.59% 0.81
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.