LOW · 3.5

CVE-2010-2008

MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string...

Vulnerability Description

MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
OracleMysql< 5.1.48
CanonicalUbuntu Linux6.06
FedoraprojectFedora13

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2008?

CVE-2010-2008 is a vulnerability with a CVSS score of 3.5 (LOW). MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string...

How severe is CVE-2010-2008?

CVE-2010-2008 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2008?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql, Canonical Ubuntu Linux, Fedoraproject Fedora.