Vulnerability Name:

CVE-2006-3081 (CCN-27212)

Assigned:2006-06-14
Published:2006-06-14
Updated:2019-12-17
Summary:mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
CVSS v3 Severity:3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Full-Disclosure Mailing List, Wed Jun 14 2006 - 12:24:15 CDT
MySQL DoS

Source: CCN
Type: Full-Disclosure Mailing List, Thu Jun 15 2006 - 00:41:30 CDT
Re: MySQL DoS

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=373913

Source: CONFIRM
Type: UNKNOWN
http://bugs.mysql.com/bug.php?id=15828

Source: MITRE
Type: CNA
CVE-2006-3081

Source: CCN
Type: MySQL Web site
MySQL AB :: MySQL Downloads

Source: CCN
Type: Mac OS X 10.4.9 and Security Update 2007-003
About the security content of Mac OS X 10.4.9 and Security Update 2007-003

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=305214

Source: APPLE
Type: UNKNOWN
APPLE-SA-2007-03-13

Source: CCN
Type: RHSA-2006-0544
mysql security update

Source: CCN
Type: RHSA-2007-0083
Low: mysql security update

Source: FULLDISC
Type: UNKNOWN
20060615 MySQL DoS

Source: CCN
Type: SA19929
MySQL Information Disclosure and Buffer Overflow Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
19929

Source: SECUNIA
Type: Vendor Advisory
20832

Source: SECUNIA
Type: Vendor Advisory
20871

Source: CCN
Type: SA24479
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
24479

Source: CCN
Type: ASA-2007-077
mysql security update (RHSA-2007-0083)

Source: CCN
Type: Apple Mac OS X Web site
Apple - Apple - Mac OS X - Leopard Sneak Peek

Source: DEBIAN
Type: UNKNOWN
DSA-1112

Source: DEBIAN
Type: DSA-1112
mysql-dfsg-4.1 -- several vulnerabilities

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2006:111

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0083

Source: BUGTRAQ
Type: UNKNOWN
20060614 MySQL DoS

Source: BUGTRAQ
Type: UNKNOWN
20060615 Re: MySQL DoS

Source: BUGTRAQ
Type: UNKNOWN
20060615 Re: MySQL DoS

Source: BID
Type: Exploit
18439

Source: CCN
Type: BID-18439
MySQL Server Str_To_Date Remote Denial Of Service Vulnerability

Source: CCN
Type: USN-306-1
MySQL 4.1 vulnerability

Source: CERT
Type: US Government Resource
TA06-208A

Source: CERT
Type: US Government Resource
TA07-072A

Source: VUPEN
Type: UNKNOWN
ADV-2007-0930

Source: XF
Type: UNKNOWN
mysql-select-dos(27212)

Source: XF
Type: UNKNOWN
mysql-select-dos(27212)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:9516

Source: UBUNTU
Type: UNKNOWN
USN-306-1

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:mysql:4.1.13:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.15:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.2:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.4:-:*:*:*:*:*:*
  • OR cpe:/a:mysql:mysql:5.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.0.18:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.16:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.18:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql:4.0.18:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.13:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.18:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.23:bk:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.15:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.16:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.2:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.0.4:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.23:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:mysql:mysql:5.1.5:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:9516
    V
    mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
    2013-04-29
    oval:org.debian:def:1112
    V
    several vulnerabilities
    2006-07-18
    oval:com.redhat.rhsa:def:20060544
    P
    RHSA-2006:0544: mysql security update (Important)
    2006-06-09
    BACK
    mysql mysql 4.1.13
    mysql mysql 4.1.15
    mysql mysql 5.0.0
    mysql mysql 5.0.1
    mysql mysql 5.0.2
    mysql mysql 5.0.3
    mysql mysql 5.0.4
    mysql mysql 5.1.5
    oracle mysql 4.0.18
    oracle mysql 4.1.4
    oracle mysql 4.1.5
    oracle mysql 4.1.7
    oracle mysql 4.1.16
    oracle mysql 5.0.18
    mysql mysql 4.0.18
    mysql mysql 4.1.13
    mysql mysql 5.0.18
    mysql mysql 5.1.23_bk
    mysql mysql 4.1.15
    mysql mysql 4.1.16
    mysql mysql 4.1.4
    mysql mysql 4.1.5
    mysql mysql 4.1.7
    mysql mysql 5.0.0
    mysql mysql 5.0.1
    mysql mysql 5.0.2
    mysql mysql 5.0.3
    mysql mysql 5.0.4
    mysql mysql 5.1.1
    mysql mysql 5.1.2
    mysql mysql 5.1.23
    mysql mysql 5.1.3
    mysql mysql 5.1.4
    mysql mysql 5.1.5
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    debian debian linux 3.1