MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T02:17:13.292Z

Reserved: 2010-05-21T00:00:00

Link: CVE-2010-2008

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-07-13T20:30:01.593

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-2008

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-07-06T00:00:00Z

Links: CVE-2010-2008 - Bugzilla

cve-icon OpenCVE Enrichment

No data.