Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysqlserver | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jul 21, 2006 |
| Freebsd | — | Upgrade mysql-server | Dec 10, 2025 | Aug 13, 2006 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jul 21, 2006 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 4.1.21 | Aug 29, 2012 | Jul 21, 2006 |
| Ubuntu | — | Upgrade mysql-server-4.1 | Nov 8, 2024 | Jul 21, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub