Vulnerability record · CVE-2009-4484 · published 30 December 2009
CVE-2009-4484: MySQL yaSSL CertDecoder::GetName stack buffer overflow
Oracle · Mysql
TaoCrypt in yaSSL before 1.9.9, as used by mysqld in MySQL 5.0.x before 5.0.90, 5.1.x before 5.1.43 and 5.5.x through 5.5.0-m2, has multiple stack-based buffer overflows in CertDecoder::GetName in src/asn.cpp. A remote attacker can trigger memory corruption by sending an X.509 client certificate with a crafted name field over an SSL connection. The flaw matters because it is reachable pre-authentication on any MySQL instance built with the affected yaSSL, and public exploit code exists.
Description
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPre-authentication remote code execution with public exploit code and very high EPSS, but the affected MySQL and yaSSL versions are long obsolete and most environments have since upgraded.
What it is
TaoCrypt in yaSSL before 1.9.9, as used by mysqld in MySQL 5.0.x before 5.0.90, 5.1.x before 5.1.43 and 5.5.x through 5.5.0-m2, has multiple stack-based buffer overflows in CertDecoder::GetName in src/asn.cpp. A remote attacker can trigger memory corruption by sending an X.509 client certificate with a crafted name field over an SSL connection. The flaw matters because it is reachable pre-authentication on any MySQL instance built with the affected yaSSL, and public exploit code exists.
Impact
An attacker gains remote code execution in the mysqld process, or at minimum crashes the daemon, causing denial of service. Because the overflow occurs during certificate parsing, it can be hit before credentials are validated.
Attack surface
Reached over the network by establishing an SSL connection to the MySQL server and supplying a crafted X.509 client certificate name field; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described.
Exploitation
Not listed in CISA KEV, but EPSS is 0.69552 (99.3rd percentile) and references include an Exploit-tagged MySQL bug report, a Metasploit module (mysql_yassl_getname) and the VulnDisco vd_mysql5 module, so working exploit code is publicly available.
What to do
- Upgrade MySQL to 5.0.90, 5.1.43 or later, or apply the vendor patch referenced in the MySQL commit list; upgrade yaSSL to 1.9.9 or later.
- Apply distribution updates for Ubuntu (USN-897-1) and Debian (DSA-1997) where packaged MySQL/MariaDB is in use.
- If patching is not immediately possible, disable SSL on the MySQL listener or restrict it to trusted networks, since the flaw is only reachable over SSL.
- Restrict network access to MySQL ports (3306/3307) to trusted hosts and require TLS client certificate validation only from known clients.
- Rebuild or replace any product embedding yaSSL below 1.9.9, including MariaDB and other bundled deployments.
Detection
- Monitor mysqld for crashes or restarts correlated with inbound SSL connections, which may indicate exploitation attempts.
- Inspect network traffic for SSL handshakes carrying unusually long or malformed X.509 client certificate name fields.
- Search host and IDS logs for known exploit artifacts such as mysql_overflow1.py or the Metasploit mysql_yassl_getname module.
- Audit MySQL builds and version banners to identify instances still linked against yaSSL versions below 1.9.9.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-4484 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-4484), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.