OSVDB ID: 10132

Title: Microsoft SQL Server Pre-Authentication Remote Overflow

Info

Disclosure

Aug 05, 2002

Discovery

Unknown

Dates

Exploit

Aug 05, 2002

Solution

Unknown

Description

A remote overflow exists in Microsoft SQL and MSDE. SQL & MSDE fail to perform proper bounds checking on port 1433 request resulting in a buffer overflow. With a specially crafted request, an attacker may be able to execute arbitrary code resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Microsoft Data Engine (MSDE)

2000
1.0

SQL Server

7.0
2000

References

Credit

  • Dave Aitel - daveBrand New Doo Dooimmunitysec.com - Immunity, Inc.


Direct URL: http://osvdb.org/36218