CVE-2006-3469

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
References
Link Resource
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375694
http://bugs.mysql.com/bug.php?id=20729
http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html
http://docs.info.apple.com/article.html?artnum=305214
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://secunia.com/advisories/21147 Vendor Advisory
http://secunia.com/advisories/21366 Vendor Advisory
http://secunia.com/advisories/24479 Vendor Advisory
http://secunia.com/advisories/31226 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-09.xml
http://www.debian.org/security/2006/dsa-1112 Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0768.html
http://www.securityfocus.com/bid/19032
http://www.ubuntu.com/usn/usn-321-1
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0930 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9827
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375694
http://bugs.mysql.com/bug.php?id=20729
http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html
http://docs.info.apple.com/article.html?artnum=305214
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://secunia.com/advisories/21147 Vendor Advisory
http://secunia.com/advisories/21366 Vendor Advisory
http://secunia.com/advisories/24479 Vendor Advisory
http://secunia.com/advisories/31226 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200608-09.xml
http://www.debian.org/security/2006/dsa-1112 Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0768.html
http://www.securityfocus.com/bid/19032
http://www.ubuntu.com/usn/usn-321-1
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0930 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9827
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mysql:mysql:4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:4.1.12:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:4.1.13:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:4.1.14:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:4.1.15:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.16:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.18:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:4.1.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.18:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.19:*:*:*:*:*:*:*

History

21 Nov 2024, 00:13

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375694 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375694 -
References () http://bugs.mysql.com/bug.php?id=20729 - () http://bugs.mysql.com/bug.php?id=20729 -
References () http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html - () http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html -
References () http://docs.info.apple.com/article.html?artnum=305214 - () http://docs.info.apple.com/article.html?artnum=305214 -
References () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html -
References () http://secunia.com/advisories/21147 - Vendor Advisory () http://secunia.com/advisories/21147 - Vendor Advisory
References () http://secunia.com/advisories/21366 - Vendor Advisory () http://secunia.com/advisories/21366 - Vendor Advisory
References () http://secunia.com/advisories/24479 - Vendor Advisory () http://secunia.com/advisories/24479 - Vendor Advisory
References () http://secunia.com/advisories/31226 - Vendor Advisory () http://secunia.com/advisories/31226 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200608-09.xml - () http://security.gentoo.org/glsa/glsa-200608-09.xml -
References () http://www.debian.org/security/2006/dsa-1112 - Patch, Vendor Advisory () http://www.debian.org/security/2006/dsa-1112 - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0768.html - () http://www.redhat.com/support/errata/RHSA-2008-0768.html -
References () http://www.securityfocus.com/bid/19032 - () http://www.securityfocus.com/bid/19032 -
References () http://www.ubuntu.com/usn/usn-321-1 - () http://www.ubuntu.com/usn/usn-321-1 -
References () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/0930 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/0930 - Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9827 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9827 -

Information

Published : 2006-07-21 14:03

Updated : 2024-11-21 00:13


NVD link : CVE-2006-3469

Mitre link : CVE-2006-3469

CVE.ORG link : CVE-2006-3469


JSON object : View

Products Affected

mysql

  • mysql

oracle

  • mysql
CWE
CWE-134

Use of Externally-Controlled Format String