Bug 201904 (CVE-2006-3469)

Summary: CVE-2006-3469 mysql server DoS
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Tom Lane <tgl>
Status: CLOSED ERRATA QA Contact: David Lawrence <dkl>
Severity: low Docs Contact:
Priority: medium    
Version: unspecifiedCC: byte, dan, hhorak
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-07-25 07:51:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2006-08-09 18:26:17 UTC
mysql server DoS

A bug was found in the mysql server which can allow an authenticated
remote users cause a temporary DoS on the server.  All clients
connected to the server will be disconnected, they will have to
reconnect to the sql server.

Affects 4.1 before 4.1.21 and 5.0 (doesn't affect 3.x)

The upstream bug is here:
http://bugs.mysql.com/bug.php?id=20729

Comment 1 Tom Lane 2006-08-09 20:35:05 UTC
Per discussion, the odds of real applications being vulnerable to this seem pretty low, so we're not going 
to turn the RHEL4 mysql package just for this --- putting it in the queue for next update.

Comment 2 Daniel Bartlett 2007-06-20 10:57:03 UTC
This is more of a concern in a shared hosting environment. Any user who has a
mysql account can cause the mysqld process to crash. I bump this bug for more
attention.

Regards,
Daniel.

Comment 7 Mark J. Cox 2007-08-21 11:05:13 UTC
moving to security response parent bug, should this deferred issue get picked up
for a future update we'll create tracking bugs with appropriate flags set at
that time.

Comment 12 Tomas Hoger 2008-05-02 11:53:57 UTC
Reproducers from the upstream bug:

select date_format('%d%s', 1);
select date_format('%Y-%m-%d %H:%i:%s', 1151414896);

Upstream commit:

http://lists.mysql.com/commits/9048


Comment 15 Red Hat Product Security 2008-07-25 07:51:01 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2008-0768.html