>" in yassl_imp.cpp. "> >",in,yassl_imp.cpp. "> SecuritySpace - CVE-2008-0226
 
 
 Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-0226
Description:Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-0226
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
BugTraq ID: 27140
http://www.securityfocus.com/bid/27140
BugTraq ID: 31681
http://www.securityfocus.com/bid/31681
Bugtraq: 20080104 Multiple vulnerabilities in yaSSL 1.7.5 (Google Search)
http://www.securityfocus.com/archive/1/485810/100/0/threaded
Bugtraq: 20080104 Pre-auth buffer-overflow in mySQL through yaSSL (Google Search)
http://www.securityfocus.com/archive/1/485811/100/0/threaded
Debian Security Information: DSA-1478 (Google Search)
http://www.debian.org/security/2008/dsa-1478
http://www.mandriva.com/security/advisories?name=MDVSA-2008:150
http://secunia.com/advisories/28324
http://secunia.com/advisories/28419
http://secunia.com/advisories/28597
http://secunia.com/advisories/29443
http://secunia.com/advisories/32222
http://securityreason.com/securityalert/3531
http://www.ubuntu.com/usn/usn-588-1
http://www.vupen.com/english/advisories/2008/0560/references
http://www.vupen.com/english/advisories/2008/2780
XForce ISS Database: yassl-inputbufferoperator-bo(39431)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39431
XForce ISS Database: yassl-processoldclienthello-bo(39429)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39429




© 1998-2025 E-Soft Inc. All rights reserved.