Security Advisory

CVE-2006-3469

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-07-18 23:00:00
Last updated 2024-08-07 18:30:34
Assigner mitre
State PUBLISHED

Description

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.