Microsoft MS-SQL Server Installation Password Caching Vulnerability
BID:5203
Info
Microsoft MS-SQL Server Installation Password Caching Vulnerability
| Bugtraq ID: | 5203 |
| Class: | Design Error |
| CVE: |
CVE-2002-0643 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 11 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Microsoft has credited Cesar Cerrudo <[email protected]> for the discovery of this vulnerability. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP3 alpha Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 alpha Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 alpha Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 alpha Microsoft SQL Server 7.0 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft MS-SQL Server Installation Password Caching Vulnerability
During the initial installation of Microsoft SQL Server 7 (including MSDE 1.0) and 2000, or when applying service packs, information, sometimes including passwords, is gathered and stored in a file on the host computer. Prior to MS-SQL Server 7.0 SP4, these passwords were stored in clear text in the file.
During the initial installation of Microsoft SQL Server 7 (including MSDE 1.0) and 2000, or when applying service packs, information, sometimes including passwords, is gathered and stored in a file on the host computer. Prior to MS-SQL Server 7.0 SP4, these passwords were stored in clear text in the file.
References
Microsoft MS-SQL Server Installation Password Caching Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-035 (Microsoft)
- Vulnerability Note VU#338195 (CERT/CC)