This application requires Javascript for optimal performance.

MySQL.YaSSL.Certificate.Packet.Buffer.Overflow

Release Date

Mar 14, 2011

Severity

high

Impact

System compromise
Denial of service

Description

This indicates s possible attack against a buffer-overflow vulnerability in yaSSL.

This issue is caused by an error when the vulnerable software handles a malformed certificate packet. It may allow remote attackers to execute arbitrary code or cause denial of service by sending a crafted certificate packet.

Affected Products

yaSSL prior to 1.9.9

Recommended Actions

Update to version 1.9.9.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4484

Reference: VID-25199