|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
(Description Provided by CVE) : Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Solution Unknown
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Vuln Dependent
|
|
Solution |
Upgrade to version 1.8.6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
yaSSL
 |
1.7.5 |
|
|
|
|
|
|
Credit |
- Luigi Auriemma - aluigi
altervista.org - http://aluigi.altervista.org
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|