4
CVSSv2

CVE-2006-3469

Published: 21/07/2006 Updated: 17/12/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Format string vulnerability in time.cc in MySQL Server 4.1 prior to 4.1.21 and 5.0 prior to 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql 4.1.11

mysql mysql 4.1.15

mysql mysql 4.1.8

oracle mysql 4.1.9

mysql mysql 5.0.16

mysql mysql 5.0.5.0.21

mysql mysql 4.1.13

oracle mysql 4.1.20

oracle mysql 4.1.6

oracle mysql 5.0.11

oracle mysql 5.0.12

oracle mysql 5.0.18

mysql mysql 4.1.12

oracle mysql 4.1.16

oracle mysql 4.1.18

oracle mysql 4.1.19

mysql mysql 5.0.10

mysql mysql 5.0.17

oracle mysql 5.0.6

oracle mysql 5.0.9

mysql mysql 4.1.14

oracle mysql 4.1.7

oracle mysql 5.0.13

mysql mysql 5.0.15

oracle mysql 5.0.19

Vendor Advisories

Jean-David Maillefer discovered a format string bug in the date_format() function’s error reporting By calling the function with invalid arguments, an authenticated user could exploit this to crash the server ...
Several local vulnerabilities have been discovered in the MySQL database server, which may lead to denial of service The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-3081 "Kanatoko" discovered that the server can be crashed with feeding NULL values to the str_to_date() function CVE-2006-3469 ...

Exploits

source: wwwsecurityfocuscom/bid/19032/info MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input This issue allows remote attackers to crash affected database servers, denying service to legitimate users Attackers must be able to execute arbitrary SQL statements ...