Buffer Overrun Vulnerability in Microsoft Data Access Components (MDAC) - 01 Aug 2002
A buffer overflow vulnerability exists in Microsoft Data Access Components (MDAC) that could result in the SQL service failing or executing arbitrary code from a potential attacker.
July 31, 2002
Reported July 31, 2002, byMicrosoft.
VERSION AFFECTED
Microsoft Data Access Components (MDAC) Versions 2.7, 2.6, and 2.5
DESCRIPTION
Abuffer overflow vulnerability exists in Microsoft Data Access Components (MDAC)that could result in the SQL service failing or executing arbitrary code from apotential attacker. This vulnerability results from an unchecked buffer in the MDAC functionsthat handle the OpenRowSet command. A potential attacker who submits a databasequery that contains a specially malformed parameter within a call to the T-SQLOpenRowSet command could exploit this vulnerability. Although MDAC ships as acomponent of all versions of Windows, this vulnerability can be exploited onlyon SQL servers.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-040to address this vulnerability and recommends that affected users the appropriatepatch mentioned in the security bulletin.
CREDIT
Discovered by DavidLitchfieldof Next Generation Security Software.
Read more about:
MicrosoftAbout the Author
You May Also Like