|
|
| |
|
| |
mysql: arbitrary code execution
| Package(s): | mysql |
CVE #(s): | CVE-2009-4484
|
| Created: | February 10, 2010 |
Updated: | March 30, 2010 |
| Description: |
From the Ubuntu advisory:
It was discovered that MySQL contained a buffer overflow when parsing
ssl certificates. A remote attacker could send crafted requests and cause a
denial of service or possibly execute arbitrary code. This issue did not
affect Ubuntu 6.06 LTS and the default compiler options for affected
releases should reduce the vulnerability to a denial of service. In the
default installation, attackers would also be isolated by the AppArmor
MySQL profile. |
| Alerts: |
|
( Log in to post comments)
|
|
|