Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
BID:5310
Info
Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
| Bugtraq ID: | 5310 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0649 CVE-2002-0729 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Nov 15 2007 12:40AM |
| Credit: | Vulnerability discovery credited to David Litchfield. |
| Vulnerable: |
Veritas Software Backup Exec for Windows Servers 9.0 Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft Data Engine 2000 |
| Not Vulnerable: |
Microsoft SQL Server 2000 SP3 |
Discussion
Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
A vulnerability in Microsoft SQL Server 2000 could allow remote attackers to access target hosts.
A problem in the SQL Server Resolution Service allows a remote attacker to execute arbitrary code on a vulnerable host. The attacker could exploit a heap-based buffer overflow in the resolution service by sending a maliciously crafted UDP packet to port 1434.
***UPDATE:
A worm that may exploit this vulnerability has been detected in the wild.
Administrators are advised to:
- Block all external access to database servers until more information is available.
- Deny access to TCP and UDP ports 1434 completely
- Implement filter rules for other ports to decrease the chances of compromise through yet unknown avenues, even if the patch for this particular vulnerability has been installed.
Cisco has released an advisory that details workaround information. Microsoft recommends that affected users apply SQL Server 2000 Service Pack 3.
A vulnerability in Microsoft SQL Server 2000 could allow remote attackers to access target hosts.
A problem in the SQL Server Resolution Service allows a remote attacker to execute arbitrary code on a vulnerable host. The attacker could exploit a heap-based buffer overflow in the resolution service by sending a maliciously crafted UDP packet to port 1434.
***UPDATE:
A worm that may exploit this vulnerability has been detected in the wild.
Administrators are advised to:
- Block all external access to database servers until more information is available.
- Deny access to TCP and UDP ports 1434 completely
- Implement filter rules for other ports to decrease the chances of compromise through yet unknown avenues, even if the patch for this particular vulnerability has been installed.
Cisco has released an advisory that details workaround information. Microsoft recommends that affected users apply SQL Server 2000 Service Pack 3.
Exploit / POC
Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
Solution:
Administrators are advised to:
- Ensure that all SQL Server processes are inactive before installing patches.
- Ensure that all installations of SQL server are patched.
- Reboot the system before restarting the SQL server.
Veritas Software Backup Exec 9.0 ships with some MSDE components and may therefore be prone to this vulnerability. Users are advised to apply the Microsoft fixes to address this vulnerability for Backup Exec.
A specific fix has been released for the Microsoft .NET Framework SDK. See the references for a link to Microsoft Knowledge Base article 813850 for instructions and download information.
Fixes are available.
Microsoft SQL Server 2000
Microsoft Data Engine 2000
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 2000 Desktop Engine
Microsoft SQL Server 2000 SP2
Solution:
Administrators are advised to:
- Ensure that all SQL Server processes are inactive before installing patches.
- Ensure that all installations of SQL server are patched.
- Reboot the system before restarting the SQL server.
Veritas Software Backup Exec 9.0 ships with some MSDE components and may therefore be prone to this vulnerability. Users are advised to apply the Microsoft fixes to address this vulnerability for Backup Exec.
A specific fix has been released for the Microsoft .NET Framework SDK. See the references for a link to Microsoft Knowledge Base article 813850 for instructions and download information.
Fixes are available.
Microsoft SQL Server 2000
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft Data Engine 2000
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE
Microsoft SQL Server 2000 SP1
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 Desktop Engine
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP2
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft Q316333
Updated cumulative patch.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
References
Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
References:
References:
- 813850 - Cannot Apply SQL Server 2000 MSDE Service Packs to MSDE Instances Insta (Microsoft)
- Analysis of Sapphire SQL Worm (Matthew Murphy
) - CERT Advisory CA-2003-04 MS-SQL Server Worm (CERT/CC)
- Microsoft Products that include MSDE 2000 (Microsoft)
- Microsoft Security Bulletin MS02-039 (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)
- PSS Security Response Team Alert - New Worm: W32.Slammer (Microsoft)
- Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! (Dave Aitel
)