yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products,
allows remote attackers to cause a denial of service (crash) via a Hello
packet containing a large size value, which triggers a buffer over-read in
the HASHwithTransform::Update function in hash.cpp.
jdstrand> dapper not affected (yassl not compiled)
Updated: 2016-01-26 17:30:17 UTC (commit 10507)