CVE-2006-2753

Publication date 1 June 2006

Last updated 24 July 2024


Ubuntu priority

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.

Status

Package Ubuntu Release Status
exim4 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 4.60-3ubuntu3.1
mysql-dfsg 7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
mysql-dfsg-5.0 7.04 feisty
Fixed 5.0.38-0ubuntu1
6.10 edgy
Fixed 5.0.24a-9ubuntu0.1
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.3

References

Related Ubuntu Security Notices (USN)

    • USN-288-3
    • PostgreSQL client vulnerabilities
    • 9 June 2006

Other references