CVE-2010-2008
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a .
Does this matter?
Lower severity and a low EPSS score (9.01%). Track it; it rarely justifies an emergency change on its own.
Description
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
- EPSS
- 9.01% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- oracle/mysql · canonical/ubuntu linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/bug.php?id=53804Exploit, Issue Tracking, Vendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.htmlThird Party Advisory
- http://secunia.com/advisories/40333Third Party Advisory
- http://secunia.com/advisories/40762Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:155Broken Link
- http://www.securityfocus.com/bid/41198Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024160Exploit, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1017-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1397-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/1918Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11869Third Party Advisory
- http://bugs.mysql.com/bug.php?id=53804Exploit, Issue Tracking, Vendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.htmlThird Party Advisory
- http://secunia.com/advisories/40333Third Party Advisory
- http://secunia.com/advisories/40762Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:155Broken Link
- http://www.securityfocus.com/bid/41198Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024160Exploit, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1017-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1397-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/1918Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11869Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.