Unrated severityNVD Advisory· Published Jan 10, 2008· Updated Apr 23, 2026
CVE-2008-0227
CVE-2008-0227
Description
yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- www.securityfocus.com/bid/27140nvdExploit
- secunia.com/advisories/28324nvdVendor Advisory
- bugs.mysql.com/33814nvd
- dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlnvd
- lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlnvd
- secunia.com/advisories/28597nvd
- secunia.com/advisories/29443nvd
- secunia.com/advisories/32222nvd
- securityreason.com/securityalert/3531nvd
- support.apple.com/kb/HT3216nvd
- www.debian.org/security/2008/dsa-1478nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/485810/100/0/threadednvd
- www.securityfocus.com/bid/31681nvd
- www.ubuntu.com/usn/usn-588-1nvd
- www.vupen.com/english/advisories/2008/0560/referencesnvd
- www.vupen.com/english/advisories/2008/2780nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39433nvd
News mentions
0No linked articles in our index yet.