OSVDB ID: 10148

Title: Microsoft SQL Server xp_enumresultset Function Overflow

Info

Disclosure

Dec 01, 2000

Discovery

Unknown

Dates

Exploit

Dec 01, 2000

Solution

Unknown

Description

A remote overflow exists in SQL Server, SQL Server Data Engine and MSDE. The programs fail to properly parse input in the xp_enumresultset() function resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code or a denial of service resulting in a loss of integrity and/or availability.

Classification

Location: Remote/Network Access Required
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

SQL Server

2000
7.0

SQL Server Data Engine

2000

Data Engine (MSDE)

1.0

References

Credit

  • Chris Anley - chrisanleyBrand New Doo Doohushmail.com -
  • David Litchfield - dlitchfieldBrand New Doo Dooatstake.com -


Direct URL: http://osvdb.org/36218