Back

MEDIUM

mysql server DoS

Published Jul 18, 2006

Description

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

Affected products

Remediation

Red Hat statement

This issue did not affect mysql packages as shipped with Red Hat Enterprise Linux 2.1, 3, or 5, and Red Hat Application Stack v1 and v2.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 18, 2006
Updated Aug 7, 2024
Reserved Jul 10, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 27, 2006