Intrusion Prevention

MySQL.yaSSL.SSL.Hello.Message.Buffer.Overflow

Description

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in the MySQL yaSSL module.
The vulnerability is due to improper handling of specially crafted packets, which could lead to the execution of arbitrary code or a Denial of Service.

Affected Products

MySQL yaSSL version 1.7.5 and earlier.

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable systems.

Recommended Actions

Allow access by trusted users only to SSL servers using yaSSL.

CVE References

CVE-2008-0227