CVE-2008-0226
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 91.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 91.60% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- yassl/yassl · mysql/mysql · oracle/mysql · apple/mac os x · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/33814Permissions Required
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlNot Applicable
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/28324Not Applicable
- http://secunia.com/advisories/28419Not Applicable
- http://secunia.com/advisories/28597Not Applicable
- http://secunia.com/advisories/29443Not Applicable
- http://secunia.com/advisories/32222Not Applicable
- http://securityreason.com/securityalert/3531Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://www.debian.org/security/2008/dsa-1478Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:150Broken Link
- http://www.securityfocus.com/archive/1/485810/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/485811/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27140Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-588-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0560/referencesPermissions Required
- http://www.vupen.com/english/advisories/2008/2780Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39429VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39431VDB Entry
- http://bugs.mysql.com/33814Permissions Required
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlNot Applicable
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/28324Not Applicable
- http://secunia.com/advisories/28419Not Applicable
- http://secunia.com/advisories/28597Not Applicable
- http://secunia.com/advisories/29443Not Applicable
- http://secunia.com/advisories/32222Not Applicable
- http://securityreason.com/securityalert/3531Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.