mysql: yaSSL certificate parsing buffer overflow (vulndisco)
Published Dec 30, 2009
7.5
HIGHCVSS 2.0
EPSS 69.55%
Description
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
Affected products
No data.
Configuration 1
Configuration 3
- 6.06
- 8.04
- 8.10
- 9.04
- 9.10
- 10.04
- 10.10
- 11.04
- 11.10
Configuration 4
- 4.0
- 5.0
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3, 4, or 5. The packages use OpenSSL and not yaSSL.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 69.55% (0.69552) | 99.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 69.55% (0.69552) | 99.28th | v5 (v2026.06.15) |
| Feb 16, 2026 | 75.82% (0.75816) | 98.88th | v4 (v2025.03.14) |
| Feb 11, 2026 | 77.76% (0.77758) | 98.96th | v4 (v2025.03.14) |
| Dec 28, 2025 | 74.61% (0.74607) | 98.80th | v4 (v2025.03.14) |
| Dec 27, 2025 | 72.08% (0.72085) | 98.70th | v4 (v2025.03.14) |
| Oct 28, 2025 | 74.61% (0.74607) | 98.79th | v4 (v2025.03.14) |
| Oct 27, 2025 | 72.08% (0.72085) | 98.69th | v4 (v2025.03.14) |
| Oct 1, 2025 | 74.61% (0.74607) | 98.82th | v4 (v2025.03.14) |
| Jun 1, 2025 | 72.08% (0.72085) | 98.66th | v4 (v2025.03.14) |
| Mar 30, 2025 | 70.17% (0.70172) | 98.57th | v4 (v2025.03.14) |
| Mar 29, 2025 | 76.80% (0.76797) | 98.64th | v4 (v2025.03.14) |
| Mar 17, 2025 | 69.42% (0.69415) | 98.55th | v4 (v2025.03.14) |
| Dec 17, 2024 | 95.77% (0.95769) | 99.59th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.14% (0.97142) | 99.84th | v3 (v2023.03.01) |
| Jun 29, 2024 | 97.01% (0.97014) | 99.76th | v3 (v2023.03.01) |
| Apr 3, 2024 | 97.17% (0.97172) | 99.79th | v3 (v2023.03.01) |
| Nov 18, 2023 | 97.21% (0.97207) | 99.78th | v3 (v2023.03.01) |
| Oct 5, 2023 | 97.15% (0.97150) | 99.72th | v3 (v2023.03.01) |
| Aug 23, 2023 | 97.19% (0.97195) | 99.72th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.33% (0.97332) | 99.80th | v3 (v2023.03.01) |
| May 8, 2023 | 97.30% (0.97301) | 99.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.14% (0.97135) | 99.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 76.36% (0.76362) | 99.38th | v2 (v2022.01.01) |
| Feb 4, 2022 | 76.36% (0.76362) | 99.24th | v2 (v2022.01.01) |
References (39)
- http://archives.neohapsis.com/archives/dailydave/2010-q1/0002.html mailing-listx_refsource_MLISTBroken Link
- http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1 x_refsource_CONFIRMBroken Link
- http://bugs.mysql.com/bug.php?id=50227 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html x_refsource_CONFIRMBroken Link
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html x_refsource_CONFIRMBroken Link
- http://intevydis.blogspot.com/2010/01/mysq-yassl-stack-overflow.html x_refsource_MISCBroken Link
- http://intevydis.com/mysql_demo.html x_refsource_MISCBroken Link
- http://intevydis.com/mysql_overflow1.py.txt x_refsource_MISCBroken Link
- http://intevydis.com/vd-list.shtml x_refsource_MISCBroken Link
- http://isc.sans.org/diary.html?storyid=7900 x_refsource_MISCThird Party Advisory
- http://lists.immunitysec.com/pipermail/dailydave/2010-January/006020.html mailing-listx_refsource_MLISTBroken Link
- http://lists.mysql.com/commits/96697 mailing-listx_refsource_MLISTPatchVendor Advisory
- http://secunia.com/advisories/37493 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38344 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38364 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38517 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38573 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://securitytracker.com/id?1023402 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://securitytracker.com/id?1023513 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://ubuntu.com/usn/usn-897-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.debian.org/security/2010/dsa-1997 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.intevydis.com/blog/?p=106 x_refsource_MISCBroken Link
- http://www.intevydis.com/blog/?p=57 x_refsource_MISCBroken Link
- http://www.metasploit.com/modules/exploit/linux/mysql/mysql_yassl_getname x_refsource_MISCThird Party Advisory
- http://www.osvdb.org/61956 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/bid/37640 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/37943 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/37974 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1397-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0233 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2010/0236 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.yassl.com/news.html#yassl199 x_refsource_CONFIRMBroken Link
- http://www.yassl.com/release.html x_refsource_CONFIRMBroken Link
- http://yassl.cvs.sourceforge.net/viewvc/yassl/yassl/taocrypt/src/asn.cpp?r1=1.13&r2=1.14 x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-4484 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=555313 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55416 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-4484
- https://www.cve.org/CVERecord?id=CVE-2009-4484
Change history (0)
No recorded changes yet.