Microsoft SQL Server OLE DB Provider Name Buffer Overflow Vulnerability
BID:4135
Info
Microsoft SQL Server OLE DB Provider Name Buffer Overflow Vulnerability
| Bugtraq ID: | 4135 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0056 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability was submitted to BugTraq on February 19th, 2002 by c c <[email protected]>. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP3 alpha Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 alpha Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 alpha Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 alpha Microsoft SQL Server 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server OLE DB Provider Name Buffer Overflow Vulnerability
Microsoft SQL Server does not perform proper bounds checking of the provider arguments to the OpenDataSource and OpenRowset functions. As a result, it is possible to cause a buffer overflow condition to occur by providing an excessively long string as a provider name in a query.
Successful exploitation may allow an attacker to execute arbitrary code with the privileges of the database.
There is a possibility that this issue may be exploited remotely, either via a distributed SQL queries or potentially via a SQL injection attack.
Microsoft SQL Server does not perform proper bounds checking of the provider arguments to the OpenDataSource and OpenRowset functions. As a result, it is possible to cause a buffer overflow condition to occur by providing an excessively long string as a provider name in a query.
Successful exploitation may allow an attacker to execute arbitrary code with the privileges of the database.
There is a possibility that this issue may be exploited remotely, either via a distributed SQL queries or potentially via a SQL injection attack.
Exploit / POC
Microsoft SQL Server OLE DB Provider Name Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SQL Server OLE DB Provider Name Buffer Overflow Vulnerability
Solution:
Microsoft has released fixes:
Microsoft SQL Server 7.0 SP3
Microsoft SQL Server 7.0 SP3 alpha
Microsoft SQL Server 2000 SP2
Solution:
Microsoft has released fixes:
Microsoft SQL Server 7.0 SP3
-
Microsoft Q318268
http://support.microsoft.com/default.aspx?scid=http://download.microso ft.com/download/sql70/Update/s71021i/WIN98MeXP/EN-US/s71021i.exe
Microsoft SQL Server 7.0 SP3 alpha
-
Microsoft Q318268
http://support.microsoft.com/default.aspx?scid=http://download.microso ft.com/download/sql70/Update/s71021a/ALPHA/EN-US/s71021a.exe
Microsoft SQL Server 2000 SP2