Vulnerability Description
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | < 5.1.48 |
| Canonical | Ubuntu Linux | 6.06 |
| Fedoraproject | Fedora | 13 |
Related Weaknesses (CWE)
References
- http://bugs.mysql.com/bug.php?id=53804ExploitIssue TrackingVendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.htmlThird Party Advisory
- http://secunia.com/advisories/40333Third Party Advisory
- http://secunia.com/advisories/40762Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:155Broken Link
- http://www.securityfocus.com/bid/41198ExploitThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1024160ExploitThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1017-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1397-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/1918Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Third Party Advisory
- http://bugs.mysql.com/bug.php?id=53804ExploitIssue TrackingVendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.htmlThird Party Advisory
FAQ
What is CVE-2010-2008?
CVE-2010-2008 is a vulnerability with a CVSS score of 3.5 (LOW). MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string...
How severe is CVE-2010-2008?
CVE-2010-2008 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2008?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql, Canonical Ubuntu Linux, Fedoraproject Fedora.