3.5
CVE-2010-2008
- EPSS 9.01%
- Veröffentlicht 13.07.2010 20:30:01
- Zuletzt bearbeitet 16.06.2026 23:19:48
- Erkennungen
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 6.06
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 10.10
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Fedoraproject ≫ Fedora Version 13
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.01% | 0.946 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:N/A:P
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
http://www.ubuntu.com/usn/USN-1397-1
http://bugs.mysql.com/bug.php?id=53804
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.html
http://secunia.com/advisories/40333
http://secunia.com/advisories/40762
http://www.mandriva.com/security/advisories?name=MDVSA-2010:155
http://www.securityfocus.com/bid/41198
http://www.securitytracker.com/id?1024160
http://www.ubuntu.com/usn/USN-1017-1
http://www.vupen.com/english/advisories/2010/1918
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11869