CVE-2006-3469

Publication date 21 July 2006

Last updated 17 July 2025


Ubuntu priority

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

Status

Package Ubuntu Release Status
mysql-dfsg 7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
mysql-dfsg-5.0 7.04 feisty
Fixed 5.0.38-0ubuntu1
6.10 edgy
Fixed 5.0.24a-9ubuntu0.1
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.3

References

Related Ubuntu Security Notices (USN)

    • USN-321-1
    • mysql-dfsg-4.1 vulnerability
    • 21 July 2006

Other references