Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
BID:5312
Info
Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
| Bugtraq ID: | 5312 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Jul 25 2002 12:00AM |
| Credit: | Discovery credited to David Litchfield of Next Generation Security Software Ltd. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 |
| Not Vulnerable: |
Microsoft SQL Server 2000 SP3 |
Discussion
Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
Microsoft SQL Server 2000 uses a keep-alive mechanism which operates through the Resolution Service.
If a particularly crafted data packet is sent to the SQL Server's keep-alive function, it will respond with an identical packet. If one such packet was sent to an SQL Server from another SQL Server, they would begin an infinite loop of keep-alive packets. Eventually, the servers will consume all available resources, resulting in a denial of services.
Microsoft SQL Server 2000 uses a keep-alive mechanism which operates through the Resolution Service.
If a particularly crafted data packet is sent to the SQL Server's keep-alive function, it will respond with an identical packet. If one such packet was sent to an SQL Server from another SQL Server, they would begin an infinite loop of keep-alive packets. Eventually, the servers will consume all available resources, resulting in a denial of services.
Exploit / POC
Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
Solution:
Fixes available:
Microsoft SQL Server 2000
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 2000 SP2
Solution:
Fixes available:
Microsoft SQL Server 2000
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP1
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP2
-
Microsoft Q323875_SQL2000_SP2_en
http://download.microsoft.com/download/SQLSVR2000/Patch/Q323875/W98NT4 2KMeXP/EN-US/Q323875_SQL2000_SP2_en.EXE -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
References
Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-039 (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)
- Technet Security (Microsoft)
- Vulnerability Note VU#370308 (CERT/CC)