Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
BID:5311
Info
Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
| Bugtraq ID: | 5311 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0649 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Vulnerability discovery credited to David Litchfield. |
| Vulnerable: |
Veritas Software Backup Exec for Windows Servers 9.0 Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft Data Engine 2000 |
| Not Vulnerable: |
Microsoft SQL Server 2000 SP3a Microsoft SQL Server 2000 SP3 |
Discussion
Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
A vulnerability has been discovered in Microsoft SQL Server 2000 that could make it possible for remote attackers to gain access to target hosts.
A problem in the SQL Server Resolution Service makes it possible for a remote user to execute arbitrary code on a vulnerable host. An attacker could exploit a stack-based overflow in the resolution service by sending a maliciously crafted UDP packet to port 1434.
It has been reported that a vulnerable version of MSDE 2000 is automatically installed with Internet Explorer 6 on .NET servers.
***UPDATE:
A worm that may exploit this vulnerability has been detected in the wild.
Administrators are advised to block all external access to database servers until more information is available. Access to TCP and UDP ports 1434 should be denied completely. Additionally, implementing filter rules for other ports may also decrease the chances of compromise through yet unknown avenues. This should be done even if the patch for this particular vulnerability has been installed.
Cisco has released an advisory that details workaround information. Microsoft recommends that affected users apply SQL Server 2000 Service Pack 3.
BlackBoard 5.5.1 Level 3 users can apply SQL Server 2000 Service Pack 3. Users are advised to contact BlackBoard for further information.
A vulnerability has been discovered in Microsoft SQL Server 2000 that could make it possible for remote attackers to gain access to target hosts.
A problem in the SQL Server Resolution Service makes it possible for a remote user to execute arbitrary code on a vulnerable host. An attacker could exploit a stack-based overflow in the resolution service by sending a maliciously crafted UDP packet to port 1434.
It has been reported that a vulnerable version of MSDE 2000 is automatically installed with Internet Explorer 6 on .NET servers.
***UPDATE:
A worm that may exploit this vulnerability has been detected in the wild.
Administrators are advised to block all external access to database servers until more information is available. Access to TCP and UDP ports 1434 should be denied completely. Additionally, implementing filter rules for other ports may also decrease the chances of compromise through yet unknown avenues. This should be done even if the patch for this particular vulnerability has been installed.
Cisco has released an advisory that details workaround information. Microsoft recommends that affected users apply SQL Server 2000 Service Pack 3.
BlackBoard 5.5.1 Level 3 users can apply SQL Server 2000 Service Pack 3. Users are advised to contact BlackBoard for further information.
Exploit / POC
Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
An exploit has been released as part of the MetaSploit Framework 2.0.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code available:
An exploit has been released as part of the MetaSploit Framework 2.0.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code available:
Solution / Fix
Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
Solution:
Prior to installing the fixes, administrators are advised to ensure that all SQL Server processes are inactive. Ensure that all installations of SQL server are patched and reboot the system before restarting the SQL server.
Veritas Software Backup Exec 9.0 ships with some MSDE components and may therefore be prone to this vulnerability. Users are advised to apply the Microsoft fixes to address this vulnerability for Backup Exec.
Microsoft has released SQL Server 2000 SP3a, which contains all of the fixes from SP3. This service pack also allows users to disable netlibs so that SQL Server 2000 will not listen on port 1434. SP3a is directed at users who have not already installed SP3 or wish to disable the netlibs. Please see the SQL Server Homepage for further details.
A specific fix has been released for the Microsoft .NET Framework SDK. See the References section for a link to Microsoft Knowledge Base article 813850 for instructions and download information.
Fixes available:
Microsoft SQL Server 2000
Microsoft Data Engine 2000
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 2000 Desktop Engine
Microsoft SQL Server 2000 SP2
Solution:
Prior to installing the fixes, administrators are advised to ensure that all SQL Server processes are inactive. Ensure that all installations of SQL server are patched and reboot the system before restarting the SQL server.
Veritas Software Backup Exec 9.0 ships with some MSDE components and may therefore be prone to this vulnerability. Users are advised to apply the Microsoft fixes to address this vulnerability for Backup Exec.
Microsoft has released SQL Server 2000 SP3a, which contains all of the fixes from SP3. This service pack also allows users to disable netlibs so that SQL Server 2000 will not listen on port 1434. SP3a is directed at users who have not already installed SP3 or wish to disable the netlibs. Please see the SQL Server Homepage for further details.
A specific fix has been released for the Microsoft .NET Framework SDK. See the References section for a link to Microsoft Knowledge Base article 813850 for instructions and download information.
Fixes available:
Microsoft SQL Server 2000
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft Data Engine 2000
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE
Microsoft SQL Server 2000 SP1
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 Desktop Engine
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP2
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft Q316333
Updated cumulative patch.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
References
Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
References:
References:
- 813850 - Cannot Apply SQL Server 2000 MSDE Service Packs to MSDE Instances Insta (Microsoft)
- Analysis of Sapphire SQL Worm (Matthew Murphy
) - CERT Advisory CA-2003-04 MS-SQL Server Worm (CERT/CC)
- Microsoft Products that include MSDE 2000 (Microsoft)
- Microsoft Security Bulletin MS02-039 (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)
- PSS Security Response Team Alert - New Worm: W32.Slammer (Microsoft)
- Resources for Combating the Slammer Worm (Microsoft)
- SQL Server CAN-2002-0649 exploit (CORE Security)
- Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! (Dave Aitel
)