CVE-2006-3469

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.

Date published : 2006-07-18

http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html

http://www.securityfocus.com/bid/19032