CVE-2006-3469

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 18 Jul 2006, 23:00
Last modified:07 Aug 2024, 18:30

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
38.92% HIGH
39% probability -13.91%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

18 Jul 2006, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 18:30
Last Modified
Vulnerability information updated

Description

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 38.92% Percentile: 97%

Techniques & Countermeasures

  • CWE-134Use of Externally-Controlled Format String

    The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Systems

  • mysqlmysql

    4.1.8 | 4.1.12 | 4.1.13 | 4.1.14 | 4.1.15 | 5.0.5.0.21 | 5.0.10 | 5.0.15 | 5.0.16 | 5.0.17

  • oraclemysql

    4.1.6 | 4.1.7 | 4.1.9 | 4.1.11 | 4.1.16 | 4.1.18 | 4.1.19 | 4.1.20 | 5.0.6 | 5.0.9 | 5.0.11 | 5.0.12 | 5.0.13 | 5.0.18 | 5.0.19

References (17)