Loading
yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
Use CWE-119, Yassl vendor hub and Yassl product page to widen CVE-2008-0227 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2005-3731 and CVE-2008-0226 for nearby disclosures in the same product family.