Buffer Overrun Vulnerability in Microsoft Data Access Components (MDAC) - 01 Aug 2002

A buffer overflow vulnerability exists in Microsoft Data Access Components (MDAC) that could result in the SQL service failing or executing arbitrary code from a potential attacker.

Ken Pfeil

July 31, 2002

1 Min Read
ITPro Today logo

Reported July 31, 2002, byMicrosoft.

VERSION AFFECTED

 

  • Microsoft Data Access Components (MDAC) Versions 2.7, 2.6, and 2.5

 

DESCRIPTION

 

Abuffer overflow vulnerability exists in Microsoft Data Access Components (MDAC)that could result in the SQL service failing or executing arbitrary code from apotential attacker. This vulnerability results from an unchecked buffer in the MDAC functionsthat handle the OpenRowSet command. A potential attacker who submits a databasequery that contains a specially malformed parameter within a call to the T-SQLOpenRowSet command could exploit this vulnerability. Although MDAC ships as acomponent of all versions of Windows, this vulnerability can be exploited onlyon SQL servers.

 

VENDOR RESPONSE

 

Thevendor, Microsoft, has released SecurityBulletin MS02-040to address this vulnerability and recommends that affected users the appropriatepatch mentioned in the security bulletin.

 

CREDIT
Discovered by DavidLitchfieldof Next Generation Security Software.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like