Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
BID:30083
Info
Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
| Bugtraq ID: | 30083 |
| Class: | Design Error |
| CVE: |
CVE-2008-0085 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2008 12:00AM |
| Updated: | Feb 11 2011 03:09PM |
| Credit: | anonymous |
| Vulnerable: |
VMWare VirtualCenter 2.5.Update 3 build 1 VMWare VirtualCenter 2.5 Update 6 VMWare VirtualCenter 2.5 Update 5 VMWare VirtualCenter 2.5 Update 4 VMWare VirtualCenter 2.5 Update 2 VMWare VirtualCenter 2.5 Update 1 VMWare VirtualCenter 2.5 VMWare Vcenter Update Manager 4.1 VMWare Vcenter Update Manager 4.0 VMWare Vcenter Update Manager 1.0 VMWare vCenter 4.1 VMWare vCenter 4.0 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Internal Database (WYukon) x64 SP2 Microsoft Windows Internal Database (WYukon) x64 SP1 Microsoft Windows Internal Database (WYukon) x64 0 Microsoft Windows Internal Database (WYukon) SP2 Microsoft Windows Internal Database (WYukon) SP1 Microsoft Windows Internal Database (WYukon) 0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft SQL Server 2005 x64 Edition SP2 Microsoft SQL Server 2005 x64 Edition SP1 Microsoft SQL Server 2005 Itanium Edition SP2 Microsoft SQL Server 2005 Itanium Edition SP1 Microsoft SQL Server 2005 Itanium Edition 0 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP1 Microsoft SQL Server 2005 Express Edition SP2 Microsoft SQL Server 2005 Express Edition SP1 Microsoft SQL Server 2005 Express Edition 0 Microsoft SQL Server 2005 SP2 Microsoft SQL Server 2005 SP1 Microsoft SQL Server 2005 0 Microsoft SQL Server 2000 Itanium Edition SP4 Microsoft SQL Server 2000 Itanium Edition SP3 Microsoft SQL Server 2000 Itanium Edition SP2 Microsoft SQL Server 2000 Itanium Edition SP1 Microsoft SQL Server 2000 Itanium Edition 0 Microsoft SQL Server 2000 Desktop Engine SP4 Microsoft SQL Server 2000 Desktop Engine SP3 Microsoft SQL Server 2000 Desktop Engine SP2 Microsoft SQL Server 2000 Desktop Engine SP1 Microsoft SQL Server 2000 Desktop Engine 0 Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP4 Microsoft SQL Server 2000 SP3 Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine (MSDE) 1.0 SP4 Microsoft Data Engine (MSDE) 1.0 SP3 Microsoft Data Engine (MSDE) 1.0 SP2 Microsoft Data Engine (MSDE) 1.0 SP1 Microsoft Data Engine (MSDE) 1.0 3DM Software Disk Management Software SP2 3DM Software Disk Management Software SP1 |
| Not Vulnerable: |
VMWare Vcenter Update Manager 4.1 Update 1 VMWare vCenter 4.1 Update 1 |
Discussion
Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
Microsoft SQL Server is prone to an information-disclosure vulnerability caused by a memory-reallocation flaw.
An attacker with operator access may leverage this issue to obtain potentially sensitive information that could aid in further attacks.
Microsoft SQL Server is prone to an information-disclosure vulnerability caused by a memory-reallocation flaw.
An attacker with operator access may leverage this issue to obtain potentially sensitive information that could aid in further attacks.
Exploit / POC
Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft SQL Server 2005 Itanium Edition SP2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft SQL Server 2005 Express Edition SP2
Microsoft SQL Server 2005 SP2
Microsoft SQL Server 2000 SP4
Microsoft SQL Server 7.0 SP4
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
Microsoft Windows Internal Database (WYukon) x64 SP2
Microsoft SQL Server 2000 Itanium Edition SP4
Microsoft Windows Server 2003 Datacenter x64 Edition
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows 2000 Advanced Server SP4
3DM Software Disk Management Software SP2
3DM Software Disk Management Software SP1
Microsoft Data Engine (MSDE) 1.0 SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Internal Database (WYukon) SP2
Microsoft SQL Server 2000 Desktop Engine SP4
Microsoft SQL Server 2005 x64 Edition SP2
Microsoft Windows Server 2008 for 32-bit Systems 0
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft SQL Server 2005 Itanium Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft SQL Server 2005 Express Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft SQL Server 2005 SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft SQL Server 2000 SP4
-
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948111)
http://www.microsoft.com/downloads/details.aspx?familyid=8316BC5E-8C2D -4710-8ACC-B815CCC81CD4 -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2 -43D8-9B0A-774C81426D9E
Microsoft SQL Server 7.0 SP4
-
Microsoft Security Update for SQL Server 7.0 and MSDE 1.0 Service Pack 4 (KB948113)
http://www.microsoft.com/downloads/details.aspx?familyid=C95B2CB3-51A4 -44E4-B9F4-9416E9CE16A0 -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2 -43D8-9B0A-774C81426D9E -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948111)
http://www.microsoft.com/downloads/details.aspx?familyid=8316BC5E-8C2D -4710-8ACC-B815CCC81CD4
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft Windows Internal Database (WYukon) x64 SP2
-
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft SQL Server 2000 Itanium Edition SP4
-
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2 -43D8-9B0A-774C81426D9E -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948111)
http://www.microsoft.com/downloads/details.aspx?familyid=8316BC5E-8C2D -4710-8ACC-B815CCC81CD4
Microsoft Windows Server 2003 Datacenter x64 Edition
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
3DM Software Disk Management Software SP2
-
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf -
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7
3DM Software Disk Management Software SP1
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft Data Engine (MSDE) 1.0 SP4
-
Microsoft Security Update for SQL Server 7.0 and MSDE 1.0 Service Pack 4 (KB948113)
http://www.microsoft.com/downloads/details.aspx?familyid=C95B2CB3-51A4 -44E4-B9F4-9416E9CE16A0 -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2 -43D8-9B0A-774C81426D9E -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948111)
http://www.microsoft.com/downloads/details.aspx?familyid=8316BC5E-8C2D -4710-8ACC-B815CCC81CD4
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft Windows Internal Database (WYukon) SP2
-
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
Microsoft SQL Server 2000 Desktop Engine SP4
-
Microsoft Security Update for Windows Server 2003 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=1c0ae18b-1f17 -44b3-a337-b36e7de437a7 -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948111)
http://www.microsoft.com/downloads/details.aspx?familyid=8316BC5E-8C2D -4710-8ACC-B815CCC81CD4 -
Microsoft Security Update for SQL Server 2000 Service Pack 4 and MSDE 2000 (KB948110)
http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2 -43D8-9B0A-774C81426D9E
Microsoft SQL Server 2005 x64 Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2003 and Windows Server 2008 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=48f6aaa5-49fc -4a16-bc34-8514e214b8cf
References
Microsoft SQL Server Memory Page Reuse Information Disclosure Vulnerability
References:
References:
- Microsoft SQL Server Homepage (Microsoft)
- Microsoft Security Bulletin MS08-040 (Microsoft)