CVE-2006-3469
Summary
| CVE | CVE-2006-3469 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-21 14:03:00 UTC |
| Updated | 2019-12-17 20:16:00 UTC |
| Description | Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| rhn.redhat.com | Red Hat Support |
REDHAT |
www.redhat.com |
|
| Secunia - Advisories - Ubuntu update for mysql-dfsg-4.1 |
SECUNIA |
secunia.com |
Vendor Advisory |
| About the security content of Mac OS X 10.4.9 and Security Update 2007-003 |
CONFIRM |
docs.info.apple.com |
|
| #375694 - SECURITY: date_format('%d%s', 1) crashs server - Debian Bug report logs |
MISC |
bugs.debian.org |
|
| APPLE-SA-2007-03-13 Mac OS X v10.4.9 and Security Update 2007-003 |
APPLE |
lists.apple.com |
|
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| MySQL Server Date_Format Denial Of Service Vulnerability |
BID |
www.securityfocus.com |
|
| US-CERT Technical Cyber Security Alert TA07-072A -- Apple Updates for Multiple Vulnerabilities |
CERT |
www.us-cert.gov |
US Government Resource |
| Repository / Oval Repository |
OVAL |
oval.cisecurity.org |
|
| Secunia - Advisories - Gentoo update for mysql |
SECUNIA |
secunia.com |
Vendor Advisory |
| Red Hat update for mysql - Secunia Advisories - Vulnerability Intelligence - Secunia.com |
SECUNIA |
secunia.com |
Vendor Advisory |
| usn/usn-321-1 - Ubuntu: Linux for human beings |
UBUNTU |
www.ubuntu.com |
|
| MySQL AB :: MySQL 3.23, 4.0, 4.1 Reference Manual :: D.1.3 Changes in release 4.1.21 (19 July 2006) |
CONFIRM |
dev.mysql.com |
|
| Debian -- Security Information -- DSA-1112-1 mysql-dfsg-4.1 |
DEBIAN |
www.debian.org |
Patch, Vendor Advisory |
| Webmail - OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| MySQL Bugs: #20729: Bad date_format() call makes mysql server crash |
MISC |
bugs.mysql.com |
|
| Gentoo Linux Documentation
--
MySQL: Denial of Service |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2008-07-25 | Mark J Cox | This issue was addressed in mysql packages as shipped in Red Hat Enterprise Linux 4 via: https://rhn.redhat.com/errata/RHSA-2008-0768.html This issue did not affect mysql packages as shipped with Red Hat Enterprise Linux 2.1, 3, or 5, and Red Hat Application Stack v1 and v2. |
There are currently no legacy QID mappings associated with this CVE.