Multiple Vulnerabilities in Microsoft SQL Server 2000 - 26 Jul 2002

Microsoft has reported three new vulnerabilities in Microsoft SQL Server 2000 and Microsoft SQL Server Desktop Engine (MSDE).

Ken Pfeil

July 25, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported July 24, 2002, byMicrosoft.

VERSIONS AFFECTED

 

  • Microsoft SQL Server 2000

  • Microsoft Desktop Engine (MSDE) 2000

 

DESCRIPTION

 

Microsofthas reported three new vulnerabilities in Microsoft SQL Server 2000 andMicrosoft SQL Server Desktop Engine (MSDE). The vulnerabilities are:

  • Two buffer overrun vulnerabilities on the SQL Server Resolution Service running on port 1434. By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten, resulting in a buffer overrun.

  • A Denial of Service (DoS) vulnerability to the same service. This vulnerability involves sending spoofed source keep-alive packets to port 1434 from one SQL server to another, which could result in a never-ending keep-alive packet exchange from one server to the other and greatly diminished performance.

VENDOR RESPONSE

 

Thevendor, Microsoft, has released SecurityBulletin MS02-039(Buffer Overruns in SQL Server 2000 Resolution Service Could Enable CodeExecution) to address this vulnerability and recommends that affected usersdownload and apply the appropriate patchmentioned in the security bulletin.

 

CREDIT
Discovered by DavidLitchfield of Next Generation Security Software.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like