← Back

CVE-2009-4028

nvd nist
Published: Nov 30, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

Affected (104)

Products: Mysql: Mysql · Oracle: Mysql
1 product
Mysql
1 product
Mysql
Configuration A
104 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Up to 5.0.87
Version 5.0.0
Version 5.0.10
Version 5.0.15
Version 5.0.16
Version 5.0.17
Version 5.0.1
Version 5.0.20
Version 5.0.22.1.0.1
Version 5.0.24
Version 5.0.2
Version 5.0.30
Version 5.0.36
Version 5.0.3
Version 5.0.44
Version 5.0.4
Version 5.0.5.0.21
Version 5.0.54
Version 5.0.56
Version 5.0.5
Version 5.0.60
Version 5.0.66
Version 5.0.82
Version 5.0.84
Version 5.1.23
Version 5.1.31
Version 5.1.32
Version 5.1.34
Version 5.1.37
Version 5.1.5
Oracle
Version 5.0.0 alpha
Version 5.0.11
Version 5.0.12
Version 5.0.13
Version 5.0.14
Version 5.0.18
Version 5.0.19
Version 5.0.21
Version 5.0.22
Version 5.0.23
Version 5.0.25
Version 5.0.26
Version 5.0.27
Version 5.0.30 sp1
Version 5.0.32
Version 5.0.33
Version 5.0.37
Version 5.0.38
Version 5.0.3 beta
Version 5.0.41
Version 5.0.42
Version 5.0.45
Version 5.0.50
Version 5.0.51
Version 5.0.52
Version 5.0.6
Version 5.0.75
Version 5.0.77
Version 5.0.7
Version 5.0.81
Version 5.0.83
Version 5.0.85
Version 5.0.86
Version 5.0.8
Version 5.1.10
Version 5.1.11
Version 5.1.12
Version 5.1.13
Version 5.1.14
Version 5.1.15
Version 5.1.16
Version 5.1.17
Version 5.1.18
Version 5.1.19
Version 5.1.1
Version 5.1.20
Version 5.1.21
Version 5.1.22
Version 5.1.23 a
Version 5.1.24
Version 5.1.25
Version 5.1.26
Version 5.1.27
Version 5.1.28
Version 5.1.29
Version 5.1.2
Version 5.1.30
Version 5.1.31 sp1
Version 5.1.33
Version 5.1.34 sp1
Version 5.1.35
Version 5.1.36
Version 5.1.37 sp1
Version 5.1.38
Version 5.1.39
Version 5.1.3
Version 5.1.40
Version 5.1.40 sp1
Version 5.1.4
Version 5.1.6
Version 5.1.7
Version 5.1.8
Version 5.1.9
Version 5.1

References (24)

Source: secalert@redhat.com
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.