CVE-2008-0227

Priority
Low
Description
yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products,
allows remote attackers to cause a denial of service (crash) via a Hello
packet containing a large size value, which triggers a buffer over-read in
the HASHwithTransform::Update function in hash.cpp.
References
Bugs
Notes
 jdstrand> dapper not affected (yassl not compiled)
Assigned-to
jdstrand
Package
Upstream:needs-triage
Package
Upstream:needed
Patches:
Vendor:http://www.debian.org/security/2008/dsa-1478
More Information

Updated: 2016-03-23 03:30:32 UTC (commit 10817)