CVE-2006-3469
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Modified
Published: 18 Jul 2006, 23:00
Last modified:07 Aug 2024, 18:30
Vulnerability Summary
Overall Risk (default)
medium
34/100 CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
38.92% HIGH
39% probability -13.91%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
18 Jul 2006, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 18:30
Last Modified
Vulnerability information updated
Description
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
CVSS Metrics
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 38.92%• Percentile: 97%
Techniques & Countermeasures
- CWE-134•Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Affected Systems
- mysql•mysql
4.1.8 | 4.1.12 | 4.1.13 | 4.1.14 | 4.1.15 | 5.0.5.0.21 | 5.0.10 | 5.0.15 | 5.0.16 | 5.0.17
- oracle•mysql
4.1.6 | 4.1.7 | 4.1.9 | 4.1.11 | 4.1.16 | 4.1.18 | 4.1.19 | 4.1.20 | 5.0.6 | 5.0.9 | 5.0.11 | 5.0.12 | 5.0.13 | 5.0.18 | 5.0.19
References (17)
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html
- http://security.gentoo.org/glsa/glsa-200608-09.xml
- http://www.securityfocus.com/bid/19032
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://secunia.com/advisories/31226
- http://docs.info.apple.com/article.html?artnum=305214
- http://www.redhat.com/support/errata/RHSA-2008-0768.html
- http://www.ubuntu.com/usn/usn-321-1
- http://secunia.com/advisories/21147
- http://secunia.com/advisories/21366
- http://bugs.mysql.com/bug.php?id=20729
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375694
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9827
- http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html
- http://www.debian.org/security/2006/dsa-1112
- http://www.vupen.com/english/advisories/2007/0930
- http://secunia.com/advisories/24479