// For flags

CVE-2006-3486

 

Severity Score

2.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability

** IMPUGNADA ** Desbordamiento de búfer por superación del límite en la función Instance_options::complete_initialization de instance_options.cc en el Instance Manager de MySQL antes de 5.0.23 y 5.1 antes de 5.1.12 podría permitir a usuarios locales provocar una denegación de servicio (caída de aplicación) mediante vectores sin especificar, lo que dispara el desbordamiento cuando se llama a la función convert_dirname. NOTA: el fabricante ha impugnado este problema por email a CVE, diciendo que solamente es explotable cuando el usuario tiene acceso al archivo de configuración o al demonio Instance Manager. Debido a su funcionalidad prevista, este nivel de acceso ya permitiría al usuario interrumpir la operación del programa, por lo cual esto no transpasa los límites de seguridad y no es una vulnerabilidad.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-07-10 CVE Reserved
  • 2006-07-10 CVE Published
  • 2023-12-03 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.0
Search vendor "Mysql" for product "Mysql" and version "5.0.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.2
Search vendor "Mysql" for product "Mysql" and version "5.0.2"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.3
Search vendor "Mysql" for product "Mysql" and version "5.0.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.4
Search vendor "Mysql" for product "Mysql" and version "5.0.4"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5
Search vendor "Mysql" for product "Mysql" and version "5.0.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.10
Search vendor "Mysql" for product "Mysql" and version "5.0.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.15
Search vendor "Mysql" for product "Mysql" and version "5.0.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.16
Search vendor "Mysql" for product "Mysql" and version "5.0.16"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.17
Search vendor "Mysql" for product "Mysql" and version "5.0.17"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.20
Search vendor "Mysql" for product "Mysql" and version "5.0.20"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.5
Search vendor "Mysql" for product "Mysql" and version "5.1.5"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.6
Search vendor "Oracle" for product "Mysql" and version "5.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.7
Search vendor "Oracle" for product "Mysql" and version "5.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.8
Search vendor "Oracle" for product "Mysql" and version "5.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.9
Search vendor "Oracle" for product "Mysql" and version "5.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.11
Search vendor "Oracle" for product "Mysql" and version "5.0.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.12
Search vendor "Oracle" for product "Mysql" and version "5.0.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.13
Search vendor "Oracle" for product "Mysql" and version "5.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.14
Search vendor "Oracle" for product "Mysql" and version "5.0.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.18
Search vendor "Oracle" for product "Mysql" and version "5.0.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.19
Search vendor "Oracle" for product "Mysql" and version "5.0.19"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.21
Search vendor "Oracle" for product "Mysql" and version "5.0.21"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.22
Search vendor "Oracle" for product "Mysql" and version "5.0.22"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.1
Search vendor "Oracle" for product "Mysql" and version "5.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.2
Search vendor "Oracle" for product "Mysql" and version "5.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.3
Search vendor "Oracle" for product "Mysql" and version "5.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.4
Search vendor "Oracle" for product "Mysql" and version "5.1.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.6
Search vendor "Oracle" for product "Mysql" and version "5.1.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.7
Search vendor "Oracle" for product "Mysql" and version "5.1.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.8
Search vendor "Oracle" for product "Mysql" and version "5.1.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.9
Search vendor "Oracle" for product "Mysql" and version "5.1.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.10
Search vendor "Oracle" for product "Mysql" and version "5.1.10"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.11
Search vendor "Oracle" for product "Mysql" and version "5.1.11"
-
Affected