Novell Home

CVE-2009-4484

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-4484 at MITRE

Description

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entries: 567977, 604528

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE CORE 9 for AMD64 and Intel EM64T
  • mysql >= 4.0.18-32.40
  • mysql-Max >= 4.0.18-32.40
  • mysql-client >= 4.0.18-32.40
  • mysql-devel >= 4.0.18-32.40
  • mysql-shared >= 4.0.18-32.40
Builds
YOU Patch Nr: 12756
SUSE Linux Enterprise Desktop 10 SP3 for x86
  • mysql >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
  • mysql >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-32bit >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
SUSE Linux Enterprise Server for SAP 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-32bit >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise SDK 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-bench >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise SDK 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-bench >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-x86 >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise SDK 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-bench >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-64bit >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise SDK 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-bench >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-32bit >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise Server 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise Server 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-x86 >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise Server 10 SP3
  • mysql >= 5.0.26-12.28.1
  • mysql-Max >= 5.0.26-12.28.1
  • mysql-client >= 5.0.26-12.28.1
  • mysql-devel >= 5.0.26-12.28.1
  • mysql-shared >= 5.0.26-12.28.1
  • mysql-shared-64bit >= 5.0.26-12.28.1
sled10-sp3.x86-64
sle10-sp3-sdk.ppc
sles10-sp3-debuginfo.x86-64
sle10-sp3-sdk.ia64
sle10-sp3-sdk.s390x
sles10-sp3-debuginfo.ppc
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.x86
sles10-sp3-debuginfo.s390x
sles10-sp3.s390x
sles10-sp3.ppc
sled10-sp3.x86
sles10-sp3-debuginfo.ia64
ZYPP Patch Nr: 6899
SUSE Linux Enterprise Server for SAP 10 SP2
  • mysql >= 5.0.26-12.24.5
  • mysql-Max >= 5.0.26-12.24.5
  • mysql-client >= 5.0.26-12.24.5
  • mysql-devel >= 5.0.26-12.24.5
  • mysql-shared >= 5.0.26-12.24.5
  • mysql-shared-32bit >= 5.0.26-12.24.5
sles10-sp2.s390x
sles10-sp2.ia64
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sles10-sp2-debuginfo.ia64
sles10-sp2-debuginfo.s390x
sles10-sp2-debuginfo.x86
ZYPP Patch Nr: 6897
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.24.5
  • mysql-Max >= 5.0.26-12.24.5
  • mysql-bench >= 5.0.26-12.24.5
  • mysql-client >= 5.0.26-12.24.5
  • mysql-devel >= 5.0.26-12.24.5
  • mysql-shared >= 5.0.26-12.24.5
sles10-sp2.s390x
sles10-sp2.ia64
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sles10-sp2-debuginfo.ia64
sles10-sp2-debuginfo.s390x
sles10-sp2-debuginfo.x86
ZYPP Patch Nr: 6897
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.24.5
  • mysql-Max >= 5.0.26-12.24.5
  • mysql-bench >= 5.0.26-12.24.5
  • mysql-client >= 5.0.26-12.24.5
  • mysql-devel >= 5.0.26-12.24.5
  • mysql-shared >= 5.0.26-12.24.5
  • mysql-shared-x86 >= 5.0.26-12.24.5
sles10-sp2.s390x
sles10-sp2.ia64
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sles10-sp2-debuginfo.ia64
sles10-sp2-debuginfo.s390x
sles10-sp2-debuginfo.x86
ZYPP Patch Nr: 6897
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.24.5
  • mysql-Max >= 5.0.26-12.24.5
  • mysql-bench >= 5.0.26-12.24.5
  • mysql-client >= 5.0.26-12.24.5
  • mysql-devel >= 5.0.26-12.24.5
  • mysql-shared >= 5.0.26-12.24.5
  • mysql-shared-64bit >= 5.0.26-12.24.5
sles10-sp2.s390x
sles10-sp2.ia64
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sles10-sp2-debuginfo.ia64
sles10-sp2-debuginfo.s390x
sles10-sp2-debuginfo.x86
ZYPP Patch Nr: 6897
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.24.5
  • mysql-Max >= 5.0.26-12.24.5
  • mysql-bench >= 5.0.26-12.24.5
  • mysql-client >= 5.0.26-12.24.5
  • mysql-devel >= 5.0.26-12.24.5
  • mysql-shared >= 5.0.26-12.24.5
  • mysql-shared-32bit >= 5.0.26-12.24.5
sles10-sp2.s390x
sles10-sp2.ia64
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sles10-sp2-debuginfo.ia64
sles10-sp2-debuginfo.s390x
sles10-sp2-debuginfo.x86
ZYPP Patch Nr: 6897

© 2014 Novell