MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jul 13, 2010 |
| Suse | — | Upgrade libmysqlclient_r16Upgrade mysql-testUpgrade libmysqlclient16-32bitUpgrade libmysqlclient-develUpgrade libmysqlclient_r16-32bitUpgrade mysql-debugUpgrade mysql-clientUpgrade mysql-ndb-extraUpgrade libmysqld-develUpgrade mysqlUpgrade mysql-toolsUpgrade libmysqlclient16Upgrade mysql-ndb-storageUpgrade mysql-benchUpgrade mysql-ndb-toolsUpgrade mysql-ndb-management | Dec 12, 2013 | Jul 13, 2010 |
| Ubuntu | — | Upgrade mysql-server-5.0Upgrade mysql-server-5.1 | Nov 8, 2024 | Jul 13, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub