← Vulnerability feed

Vulnerability record · CVE-2009-4484 · published 30 December 2009

CVE-2009-4484: MySQL yaSSL CertDecoder::GetName stack buffer overflow

Oracle · Mysql

TaoCrypt in yaSSL before 1.9.9, as used by mysqld in MySQL 5.0.x before 5.0.90, 5.1.x before 5.1.43 and 5.5.x through 5.5.0-m2, has multiple stack-based buffer overflows in CertDecoder::GetName in src/asn.cpp. A remote attacker can trigger memory corruption by sending an X.509 client certificate with a crafted name field over an SSL connection. The flaw matters because it is reachable pre-authentication on any MySQL instance built with the affected yaSSL, and public exploit code exists.

7.5 CVSS 2.0 High EPSS 70% · top 0.7% CWE-787 · Out-of-bounds write
7.5CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
72References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityPre-authentication remote code execution with public exploit code and very high EPSS, but the affected MySQL and yaSSL versions are long obsolete and most environments have since upgraded.

What it is

TaoCrypt in yaSSL before 1.9.9, as used by mysqld in MySQL 5.0.x before 5.0.90, 5.1.x before 5.1.43 and 5.5.x through 5.5.0-m2, has multiple stack-based buffer overflows in CertDecoder::GetName in src/asn.cpp. A remote attacker can trigger memory corruption by sending an X.509 client certificate with a crafted name field over an SSL connection. The flaw matters because it is reachable pre-authentication on any MySQL instance built with the affected yaSSL, and public exploit code exists.

Impact

An attacker gains remote code execution in the mysqld process, or at minimum crashes the daemon, causing denial of service. Because the overflow occurs during certificate parsing, it can be hit before credentials are validated.

Attack surface

Reached over the network by establishing an SSL connection to the MySQL server and supplying a crafted X.509 client certificate name field; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described.

Exploitation

Not listed in CISA KEV, but EPSS is 0.69552 (99.3rd percentile) and references include an Exploit-tagged MySQL bug report, a Metasploit module (mysql_yassl_getname) and the VulnDisco vd_mysql5 module, so working exploit code is publicly available.

What to do

  • Upgrade MySQL to 5.0.90, 5.1.43 or later, or apply the vendor patch referenced in the MySQL commit list; upgrade yaSSL to 1.9.9 or later.
  • Apply distribution updates for Ubuntu (USN-897-1) and Debian (DSA-1997) where packaged MySQL/MariaDB is in use.
  • If patching is not immediately possible, disable SSL on the MySQL listener or restrict it to trusted networks, since the flaw is only reachable over SSL.
  • Restrict network access to MySQL ports (3306/3307) to trusted hosts and require TLS client certificate validation only from known clients.
  • Rebuild or replace any product embedding yaSSL below 1.9.9, including MariaDB and other bundled deployments.

Detection

  • Monitor mysqld for crashes or restarts correlated with inbound SSL connections, which may indicate exploitation attempts.
  • Inspect network traffic for SSL handshakes carrying unusually long or malformed X.509 client certificate name fields.
  • Search host and IDS logs for known exploit artifacts such as mysql_overflow1.py or the Metasploit mysql_yassl_getname module.
  • Audit MySQL builds and version banners to identify instances still linked against yaSSL versions below 1.9.9.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/dailydave/2010-q1/0002.html Broken Link
http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1 Broken Link
http://bugs.mysql.com/bug.php?id=50227 ExploitIssue TrackingVendor Advisory
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html Broken Link
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html Broken Link
http://intevydis.blogspot.com/2010/01/mysq-yassl-stack-overflow.html Broken Link
http://intevydis.com/mysql_demo.html Broken Link
http://intevydis.com/mysql_overflow1.py.txt Broken Link
http://intevydis.com/vd-list.shtml Broken Link
http://isc.sans.org/diary.html?storyid=7900 Third Party Advisory
http://lists.immunitysec.com/pipermail/dailydave/2010-January/006020.html Broken Link
http://lists.mysql.com/commits/96697 PatchVendor Advisory
http://secunia.com/advisories/37493 Third Party Advisory
http://secunia.com/advisories/38344 Third Party Advisory
http://secunia.com/advisories/38364 Third Party Advisory
http://secunia.com/advisories/38517 Third Party Advisory
http://secunia.com/advisories/38573 Third Party Advisory
http://securitytracker.com/id?1023402 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1023513 Third Party AdvisoryVDB Entry
http://ubuntu.com/usn/usn-897-1 Third Party Advisory
http://www.debian.org/security/2010/dsa-1997 Third Party Advisory
http://www.intevydis.com/blog/?p=106 Broken Link
http://www.intevydis.com/blog/?p=57 Broken Link
http://www.metasploit.com/modules/exploit/linux/mysql/mysql_yassl_getname Third Party Advisory
http://www.osvdb.org/61956 Broken Link
http://www.securityfocus.com/bid/37640 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/37943 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/37974 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-1397-1 Third Party Advisory
http://www.vupen.com/english/advisories/2010/0233 Third Party Advisory
http://www.vupen.com/english/advisories/2010/0236 Third Party Advisory
http://www.yassl.com/news.html#yassl199 Broken Link
http://www.yassl.com/release.html Broken Link
http://yassl.cvs.sourceforge.net/viewvc/yassl/yassl/taocrypt/src/asn.cpp?r1=1.13&r2=1.14 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=555313 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/55416 Third Party AdvisoryVDB Entry
http://archives.neohapsis.com/archives/dailydave/2010-q1/0002.html Broken Link
http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1 Broken Link
http://bugs.mysql.com/bug.php?id=50227 ExploitIssue TrackingVendor Advisory
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html Broken Link

Track CVE-2009-4484 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2009-4484), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.