CVE-2006-3486
Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P
- Base score: 2.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.65%
- Percentile among all scored CVEs: 50
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-189
References
- http://bugs.mysql.com/bug.php?id=20622
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-23.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-12.html
- http://www.vupen.com/english/advisories/2006/2700
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27635
- http://bugs.mysql.com/bug.php?id=20622
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-23.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-12.html
- http://www.vupen.com/english/advisories/2006/2700
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27635
Raw JSON (NVD)
Show
{
"id": "CVE-2006-3486",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-07-10T21:05:00.000",
"references": [
{
"url": "http://bugs.mysql.com/bug.php?id=20622",
"source": "cve@mitre.org"
},
{
"url": "http://dev.mysql.com/doc/refman/5.0/en/news-5-0-23.html",
"source": "cve@mitre.org"
},
{
"url": "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-12.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2700",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27635",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.mysql.com/bug.php?id=20622",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://dev.mysql.com/doc/refman/5.0/en/news-5-0-23.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://dev.mysql.com/doc/refman/5.1/en/news-5-1-12.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2700",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27635",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability"
},
{
"lang": "es",
"value": "** IMPUGNADA ** Desbordamiento de búfer por superación del límite en la función Instance_options::complete_initialization de instance_options.cc en el Instance Manager de MySQL antes de 5.0.23 y 5.1 antes de 5.1.12 podría permitir a usuarios locales provocar una denegación de servicio (caída de aplicación) mediante vectores sin especificar, lo que dispara el desbordamiento cuando se llama a la función convert_dirname. NOTA: el fabricante ha impugnado este problema por email a CVE, diciendo que solamente es explotable cuando el usuario tiene acceso al archivo de configuración o al demonio Instance Manager. Debido a su funcionalidad prevista, este nivel de acceso ya permitiría al usuario interrumpir la operación del programa, por lo cual esto no transpasa los límites de seguridad y no es una vulnerabilidad."
}
],
"lastModified": "2026-06-16T22:27:10.090",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC198CDB-CAC0-41DD-9FCD-42536E7FE11A"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B77A2761-2B44-4061-9C29-A54F90A1AD83"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B3AD851-056F-4E57-B85B-4AC5A5A20C0C"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD24EA8C-4FCA-4F40-B2EA-7DFA49432483"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "754B78F2-A03C-40BE-812B-F5E57B93D20B"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "575039BD-A8B6-4459-B5F0-F220A94650EA"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "542B23CB-7535-4EF7-B926-466A5161A0D4"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45E686C3-4100-465C-9F45-068580B496E5"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E9F09D8-6FAE-4A5B-AE04-248CD52C5FF4"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB618DB2-6B00-4E99-8232-937D2C51986B"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.0.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "665E063D-355D-4A5A-A05F-36BF582DE36F"
},
{
"criteria": "cpe:2.3:a:mysql:mysql:5.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35BED939-3366-4CBF-B6BF-29C0C42E97F7"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1668BB5B-E7FB-4430-B8D5-89E308F5DD39"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3F44DA1-1509-4AC7-AB6B-2B2A834A16AC"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A2D6DF6-FE5D-428F-BCEB-E7832C2B4FE4"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7777E919-FD4B-452B-88D7-165410C703F2"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A56ACB60-EC2C-45AF-B923-B3A90A2F7AE1"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67C52D66-3BCA-4854-BF09-CB6DF1AC0E48"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF54CC8D-B736-461D-B693-686E862EF969"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E5EADE4-9E1B-4A1C-B3B5-ACF1287A19E7"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "053ACE9B-A146-42C0-ADB2-47F6119965D8"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30B4F891-2A03-45A8-A49C-7F8B8F7D8407"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69E62AC4-954E-476C-98BE-C138E328AE7B"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.0.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B88385C-F5FB-401F-80D5-5BF11CE3C19D"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73F49A1D-BCA3-4772-8AB3-621CCC997B3A"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F719DD8E-8379-43C3-97F9-DE350E457F7F"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "342BB65B-1358-441C-B59A-1756BCC6414A"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8589B1E7-0D6D-44B4-A36E-8225C5D15828"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88FEEE64-899F-4F55-B829-641706E29E32"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8597F56-BB14-480C-91CD-CAB96A9DDD8D"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F4C5C88-95A7-4DDA-BC2F-CAFA47B0D67A"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5EB2323C-EFE2-407A-9AE9-8717FA9F8625"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6341F695-6034-4CC1-9485-ACD3A0E1A079"
},
{
"criteria": "cpe:2.3:a:oracle:mysql:5.1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1DF5F19-ECD9-457F-89C6-6F0271CF4766"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "We do not consider this issue to have security implications, and therefore have no plans to issue MySQL updates for Red Hat Enterprise Linux 2.1, 3, or 4 to correct this issue.",
"lastModified": "2006-07-19T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}