Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
BID:30118
Info
Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
| Bugtraq ID: | 30118 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0106 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2008 12:00AM |
| Updated: | Feb 11 2011 03:09PM |
| Credit: | anonymous |
| Vulnerable: |
VMWare VirtualCenter 2.5.Update 3 build 1 VMWare VirtualCenter 2.5 Update 6 VMWare VirtualCenter 2.5 Update 5 VMWare VirtualCenter 2.5 Update 4 VMWare VirtualCenter 2.5 Update 2 VMWare VirtualCenter 2.5 Update 1 VMWare VirtualCenter 2.5 VMWare Vcenter Update Manager 4.1 VMWare Vcenter Update Manager 4.0 VMWare Vcenter Update Manager 1.0 VMWare vCenter 4.1 VMWare vCenter 4.0 Microsoft SQL Server 2005 x64 Edition SP2 Microsoft SQL Server 2005 x64 Edition SP1 Microsoft SQL Server 2005 Itanium Edition SP2 Microsoft SQL Server 2005 Itanium Edition SP1 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2 Microsoft SQL Server 2005 Express Edition with Advanced Serv SP1 Microsoft SQL Server 2005 Express Edition SP2 Microsoft SQL Server 2005 Express Edition SP1 Microsoft SQL Server 2005 SP2 Microsoft SQL Server 2005 SP1 |
| Not Vulnerable: |
VMWare Vcenter Update Manager 4.1 Update 1 VMWare vCenter 4.1 Update 1 |
Discussion
Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
Microsoft SQL Server is prone to a remote memory-corruption vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Authenticated attackers can exploit this issue to execute arbitrary code and completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
Microsoft SQL Server is prone to a remote memory-corruption vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Authenticated attackers can exploit this issue to execute arbitrary code and completely compromise affected computers. Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
Microsoft SQL Server 2005 Itanium Edition SP2
Microsoft SQL Server 2005 x64 Edition SP2
Microsoft SQL Server 2005 Express Edition SP2
Microsoft SQL Server 2005 SP2
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3
Microsoft SQL Server 2005 Itanium Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft SQL Server 2005 x64 Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7
Microsoft SQL Server 2005 Express Edition SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3
Microsoft SQL Server 2005 SP2
-
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948109)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9851CC-2C4C -4190-872C-84993A7623B7 -
Microsoft Security Update for SQL Server 2005 Service Pack 2 (KB948108)
http://www.microsoft.com/downloads/details.aspx?familyid=A60BB7E7-EF4E -4CBD-B63A-0AD7BD1402B3
References
Microsoft SQL Server INSERT Statement Remote Memory Corruption Vulnerability
References:
References:
- Microsoft SQL Server Homepage (Microsoft)
- Microsoft Security Bulletin MS08-040 (Microsoft)