MySQL Server Date_Format Denial Of Service Vulnerability
BID:19032
CVE-2006-3469 |Info
MySQL Server Date_Format Denial Of Service Vulnerability
| Bugtraq ID: | 19032 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-3469 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Jul 25 2008 03:48AM |
| Credit: | This issue was discovered by Christian Hammers. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Slackware Linux 10.2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 MySQL AB MySQL 5.1.5 MySQL AB MySQL 5.0.18 MySQL AB MySQL 5.0.4 MySQL AB MySQL 5.0.3 MySQL AB MySQL 5.0.2 MySQL AB MySQL 5.0.1 MySQL AB MySQL 5.0 .0-0 MySQL AB MySQL 4.1.16 MySQL AB MySQL 4.1.15 MySQL AB MySQL 4.1.13 MySQL AB MySQL 4.1.12 MySQL AB MySQL 4.1.11 MySQL AB MySQL 4.1.7 MySQL AB MySQL 4.1.5 MySQL AB MySQL 4.1.4 MySQL AB MySQL 4.0.18 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 |
| Not Vulnerable: |
MySQL AB MySQL 5.1.6 MySQL AB MySQL 5.0.19 MySQL AB MySQL 4.1.18 Apple Mac OS X Server 10.4.9 |
Discussion
MySQL Server Date_Format Denial Of Service Vulnerability
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions prior to MySQL 4.1.18, 5.0.19, and 5.1.6 are vulnerable.
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions prior to MySQL 4.1.18, 5.0.19, and 5.1.6 are vulnerable.
Exploit / POC
MySQL Server Date_Format Denial Of Service Vulnerability
Attackers use standard database client software to exploit this issue.
The following SQL statement will demonstrate this issue:
select date_format('%d%s', 1);
Attackers use standard database client software to exploit this issue.
The following SQL statement will demonstrate this issue:
select date_format('%d%s', 1);
Solution / Fix
MySQL Server Date_Format Denial Of Service Vulnerability
Solution:
The vendor has released fixed versions of MySQL to address this issue. Versions newer than or equal to 4.1.18, 5.0.19, or 5.1.6 include a fix for this issue.
Please see the referenced vendor advisories for more information.
Slackware Linux 10.2
Apple Mac OS X Server 10.4
Apple Mac OS X Server 10.4.1
Apple Mac OS X Server 10.4.2
Apple Mac OS X Server 10.4.3
Apple Mac OS X Server 10.4.4
Apple Mac OS X Server 10.4.5
Apple Mac OS X Server 10.4.6
Apple Mac OS X Server 10.4.7
Apple Mac OS X Server 10.4.8
MySQL AB MySQL 4.1.12
Solution:
The vendor has released fixed versions of MySQL to address this issue. Versions newer than or equal to 4.1.18, 5.0.19, or 5.1.6 include a fix for this issue.
Please see the referenced vendor advisories for more information.
Slackware Linux 10.2
-
Slackware mysql-4.1.21-i486-1_slack10.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ mysql-4.1.21-i486-1_slack10.2.tgz
Apple Mac OS X Server 10.4
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.1
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.2
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.3
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.4
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.5
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.6
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.7
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.8
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
MySQL AB MySQL 4.1.12
-
Ubuntu libmysqlclient14-dev_4.1.12-1ubuntu3.7_amd64.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14-dev_4.1.12-1ubuntu3.7_amd64.deb -
Ubuntu libmysqlclient14-dev_4.1.12-1ubuntu3.7_i386.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14-dev_4.1.12-1ubuntu3.7_i386.deb -
Ubuntu libmysqlclient14-dev_4.1.12-1ubuntu3.7_powerpc.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14-dev_4.1.12-1ubuntu3.7_powerpc.deb -
Ubuntu libmysqlclient14_4.1.12-1ubuntu3.7_amd64.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14_4.1.12-1ubuntu3.7_amd64.deb -
Ubuntu libmysqlclient14_4.1.12-1ubuntu3.7_i386.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14_4.1.12-1ubuntu3.7_i386.deb -
Ubuntu libmysqlclient14_4.1.12-1ubuntu3.7_powerpc.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/libmysqlc lient14_4.1.12-1ubuntu3.7_powerpc.deb -
Ubuntu mysql-client-4.1_4.1.12-1ubuntu3.7_amd64.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -client-4.1_4.1.12-1ubuntu3.7_amd64.deb -
Ubuntu mysql-client-4.1_4.1.12-1ubuntu3.7_i386.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -client-4.1_4.1.12-1ubuntu3.7_i386.deb -
Ubuntu mysql-client-4.1_4.1.12-1ubuntu3.7_powerpc.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -client-4.1_4.1.12-1ubuntu3.7_powerpc.deb -
Ubuntu mysql-common-4.1_4.1.12-1ubuntu3.7_all.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg-4.1/mysql-com mon-4.1_4.1.12-1ubuntu3.7_all.deb -
Ubuntu mysql-server-4.1_4.1.12-1ubuntu3.7_amd64.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -server-4.1_4.1.12-1ubuntu3.7_amd64.deb -
Ubuntu mysql-server-4.1_4.1.12-1ubuntu3.7_i386.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -server-4.1_4.1.12-1ubuntu3.7_i386.deb -
Ubuntu mysql-server-4.1_4.1.12-1ubuntu3.7_powerpc.deb
Ubuntu 5.10
http://security.ubuntu.com/ubuntu/pool/universe/m/mysql-dfsg-4.1/mysql -server-4.1_4.1.12-1ubuntu3.7_powerpc.deb
References
MySQL Server Date_Format Denial Of Service Vulnerability
References:
References:
- Changes in release 4.1.18 (27 January 2006) (MySQL)
- Changes in release 5.0.19 (04 March 2006) (MySQL)
- Changes in release 5.1.6 (01 February 2006) (MySQL)
- MySQL Bugs: #20729: Bad date_format() call makes mysql server crash (Christian Hammers)
- MySQL Homepage (Oracle)
- RHSA-2008:0768-9 mysql security, bug fix, and enhancement update (Red Hat)