Lucene search

K
saintSAINT CorporationSAINT:44AE9DD85267CB2C950344C3A9E6E4EA
HistoryAug 07, 2006 - 12:00 a.m.

Microsoft SQL Server Hello buffer overflow

2006-08-0700:00:00
SAINT Corporation
download.saintcorporation.com
11

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.961

Percentile

99.5%

Added: 08/07/2006
CVE: CVE-2002-1123
BID: 5411
OSVDB: 10132

Background

Microsoft SQL Server is a database server package for Windows platforms.

Problem

Microsoft SQL Server 2000 is affected by a buffer overflow vulnerability in the code which handles user authentication. This allows a remote attacker to execute arbitrary commands.

Resolution

Apply the patch referenced in Microsoft Security Bulletin 02-056.

References

<http://www.microsoft.com/technet/security/bulletin/ms02-056.mspx&gt;

Limitations

Exploit works on Microsoft SQL Server 2000 SP2 on Windows 2000.

Platforms

Windows

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.961

Percentile

99.5%