Debian Security Advisory 1877-1 – In MySQL 4.0.0 through 5.0.83, multiple format string vulnerabilities in the dispatch_command() function in libmysqld/sql_parse.cc in mysqld allow remote authenticated users to cause a denial of service (daemon crash) and potentially the execution of arbitrary code via format string specifiers in a database name in a COM_CREATE_DB or COM_DROP_DB request.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/80937/dsa-1877-1.txt
Source: https://packetstormsecurity.com/files/80937/Debian-Linux-Security-Advisory-1877-1.html

