Submitted by KeesCook on Fri, 2006-07-21 12:06
Referenced CVEs:
CVE-2006-3469
Description:
===========================================================
Ubuntu Security Notice USN-321-1 July 21, 2006
mysql-dfsg-4.1 vulnerability
CVE-2006-3469
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
mysql-server-4.1 4.1.12-1ubuntu3.7
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Jean-David Maillefer discovered a format string bug in the
date_format() function's error reporting. By calling the function with
invalid arguments, an authenticated user could exploit this to crash
the server.


