Release DateMar 11, 2010 |
Severitymedium |
ImpactDenial of services or System compromise |
DescriptionThis indicates s possible attack against a buffer overflow vulnerability in yaSSL which could be exploited to cause Denial of services or arbitrary code execution due to an error in the processing of SSL certificates. |
Affected ProductsyaSSL prior to 1.9.9 |
Recommended ActionsUpdate to version 1.9.9. |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2009-4484 |
Reference/shttp://www.securityfocus.com/bid/37943 (BugTraq) |