Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
BID:4231
Info
Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
| Bugtraq ID: | 4231 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0154 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Published by Cesar Cerrudo <[email protected]>. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP3 alpha Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 alpha Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 alpha Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 alpha Microsoft SQL Server 7.0 Compaq SANworks Management Appliance Compaq Open SAN Manager 1.0 c |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
A vulnerability has been reported in multiple extended stored procedures (XPs) provided with SQL Server. XPs are DLL files that perform high level functions in SQL Server.
If an extremely large parameter is passed to a vulnerble stored procedure, a buffer overflow condition will occur. Depending on the data supplied, this may cause a denial of service condition, or result in the execution of arbitrary code as the SQL Server process.
A vulnerability has been reported in multiple extended stored procedures (XPs) provided with SQL Server. XPs are DLL files that perform high level functions in SQL Server.
If an extremely large parameter is passed to a vulnerble stored procedure, a buffer overflow condition will occur. Depending on the data supplied, this may cause a denial of service condition, or result in the execution of arbitrary code as the SQL Server process.
Exploit / POC
Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
Solution:
Fixes are available:
Microsoft SQL Server 7.0 SP3
Microsoft SQL Server 7.0 SP3 alpha
Microsoft SQL Server 2000 SP2
Compaq Open SAN Manager 1.0 c
Solution:
Fixes are available:
Microsoft SQL Server 7.0 SP3
-
Microsoft Q318268
For Microsoft SQL Server 7.0 SP3.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q318268&
Microsoft SQL Server 7.0 SP3 alpha
-
Microsoft Q318268
For Microsoft SQL Server 7.0 SP3.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q318268&
Microsoft SQL Server 2000 SP2
-
Microsoft Q316333
For Microsoft SQL Server 2000 SP2.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&
Compaq Open SAN Manager 1.0 c
References
Microsoft SQL Server Multiple Extended Stored Procedure Buffer Overflow Vulnerabilities
References:
References:
- Microsoft Security Bulletin MS02-020 (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)