Lucene search

K
ubuntuUbuntuUSN-321-1
HistoryJul 21, 2006 - 12:00 a.m.

mysql-dfsg-4.1 vulnerability

2006-07-2100:00:00
ubuntu.com
44

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

AI Score

6

Confidence

Low

EPSS

0.921

Percentile

99.0%

Releases

  • Ubuntu 5.10

Details

Jean-David Maillefer discovered a format string bug in the
date_format() function’s error reporting. By calling the function with
invalid arguments, an authenticated user could exploit this to crash
the server.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.10noarchmysql-server-4.1< 4.1.12-1ubuntu3.7UNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

AI Score

6

Confidence

Low

EPSS

0.921

Percentile

99.0%