CVE-2009-4028

NameCVE-2009-4028
DescriptionThe vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mysql-5.1source(unstable)(not affected)
mysql-dfsg-5.0source(unstable)(not affected)

Notes

- mysql-5.1 <not-affected> (Vulnerable code not present)
- mysql-dfsg-5.0 <not-affected> (Vulnerable code not present)
built with --without-openssl

Search for package or bug name: Reporting problems