CVE-2010-1848
Publication date 21 May 2010
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
Status
Package | Ubuntu Release | Status |
---|---|---|
mysql-5.1 | ||
mysql-dfsg-5.0 | ||
mysql-dfsg-5.1 | ||
Patch details
Package | Patch details |
---|---|
mysql-dfsg-5.0 | |
mysql-dfsg-5.1 |
References
Related Ubuntu Security Notices (USN)
- USN-950-1
- MySQL vulnerabilities
- 9 June 2010
- USN-1397-1
- MySQL vulnerabilities
- 12 March 2012