~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2006-0903

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2006-02-27
2
 
Candidate: CVE-2006-0903
3
 
References:
4
 
 https://usn.ubuntu.com/usn/usn-274-1
5
 
 https://usn.ubuntu.com/usn/usn-274-2
6
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903
7
 
Description:
8
 
 MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms
9
 
 via SQL queries that contain the NULL character, which are not properly
10
 
 handled by the mysql_real_query function.  NOTE: this issue was originally
11
 
 reported for the mysql_query function, but the vendor states that since
12
 
 mysql_query expects a null character, this is not an issue for mysql_query.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
dapper_mysql-dfsg-5.0: released (5.0.22-0ubuntu6.06.3)
17
 
edgy_mysql-dfsg-5.0: released (5.0.24a-9ubuntu0.1)
18
 
feisty_mysql-dfsg-5.0: released (5.0.38-0ubuntu1)
19
 
devel_mysql-dfsg-5.0: released (5.0.38-0ubuntu1)
20
 
upstream_mysql-dfsg-5.0: