CVE-2010-2008: Canonical Ubuntu Linux

Low severity, CVSS 3.5. EPSS: 9% chance of exploitation in the next 30 days.

MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.

Affected products

  • Canonical Ubuntu Linux: version 6.06 only; version 8.04 only; version 9.10 only; version 10.04 only; version 10.10 only; version 11.04 only; …
  • Fedoraproject Fedora: version 13 only
  • Oracle MySQL: before 5.1.48 (fixed in 5.1.48)

Published 2010-07-13. Last modified 2026-06-16.