Multiple Vulnerabilities in Microsoft SQL Server 2000 and 7.0 - 02 Jan 2002

Multiple vulnerabilities exist in Microsoft SQL Server 2000 and 7.0.

Ken Pfeil

January 1, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported December 20, 2001, by@Stake.

VERSIONS AFFECTED

 

  • Microsoft SQL Server 2000

  • Microsoft SQL Server 7.0 

 

DESCRIPTION
Multiplevulnerabilities exist in Microsoft SQL Server 2000 and 7.0. The firstvulnerability is a result of several functions that let the SQL databasegenerate text messages. By not adequately verifying that the text fits into theallocated buffer space, a buffer overrun can result using the service's securitycontext.

 

The second vulnerability results because of a formatstring error in the C runtime functions that SQL Server calls when you installthe software on Windows XP, Windows 2000, and Windows NT 4.0 systems. Anattacker can use this vulnerability to cause a Denial of Service (DoS)condition. Users can learn specific details about these vulnerabilities on thediscoverer’s Website.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released SecurityBulletin MS01-060to address these vulnerabilities and recommends that affected users immediatelyapply the patches provided with the bulletin. Microsoft cautions users about therisk of applying the C runtime patch—if a regression error were to result fromapplying the patch, the results might be widespread and damaging.

 

CREDIT
Discovered by ChrisAnleyand Chris Wysopal of @Stake.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like