Microsoft Visual Basic / Visual Studio 'VB T-SQL ' Buffer Overflow Vulnerability
BID:2521
Info
Microsoft Visual Basic / Visual Studio 'VB T-SQL ' Buffer Overflow Vulnerability
| Bugtraq ID: | 2521 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2001 12:00AM |
| Updated: | Mar 27 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq in a BindView Security Advisory <[email protected]> on March 27, 2001. Posted in a Microsoft Security Bulletin (MS01-018) on March 27, 2001. |
| Vulnerable: |
Microsoft Visual Studio 6.0 Microsoft Visual Basic 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Visual Basic / Visual Studio 'VB T-SQL ' Buffer Overflow Vulnerability
An unchecked buffer within a parameter (lpctstrDbName) of the 'NewSPID' method, could be exploited by submitting 128 characters or more in the 'DbName'. The end result could lead to a buffer overflow condition possibly leading to the execution of arbitrary code.
An unchecked buffer within a parameter (lpctstrDbName) of the 'NewSPID' method, could be exploited by submitting 128 characters or more in the 'DbName'. The end result could lead to a buffer overflow condition possibly leading to the execution of arbitrary code.
Exploit / POC
Microsoft Visual Basic / Visual Studio 'VB T-SQL ' Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Visual Basic / Visual Studio 'VB T-SQL ' Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin (MS01-018) (Microsoft)