Microsoft SQL Server 7.0 NULL Data DoS Vulnerability
BID:817
Info
Microsoft SQL Server 7.0 NULL Data DoS Vulnerability
| Bugtraq ID: | 817 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 19 1999 12:00AM |
| Updated: | Nov 19 1999 12:00AM |
| Credit: | Posted to Bugtraq on November 19, 1999 by Kevork Belian <[email protected]>. |
| Vulnerable: |
Microsoft SQL Server 7.0 SP1 alpha Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 alpha Microsoft SQL Server 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server 7.0 NULL Data DoS Vulnerability
If Microsoft SQL Server 7.0 receives a TDS header with three or more NULL bytes as data it will crash. The crash will generate an event in the log with ID 17055 "fatal exception EXCEPTION_ACCESS VIOLATION".
If Microsoft SQL Server 7.0 receives a TDS header with three or more NULL bytes as data it will crash. The crash will generate an event in the log with ID 17055 "fatal exception EXCEPTION_ACCESS VIOLATION".
Exploit / POC
Microsoft SQL Server 7.0 NULL Data DoS Vulnerability
exploit available
exploit available
Solution / Fix
Microsoft SQL Server 7.0 NULL Data DoS Vulnerability
Solution:
Microsoft has released patches which address this issue:
Microsoft SQL Server 7.0 SP1
Microsoft SQL Server 7.0 SP1 alpha
Microsoft SQL Server 7.0
Solution:
Microsoft has released patches which address this issue:
Microsoft SQL Server 7.0 SP1
-
Microsoft S70761i.exe
Intel
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=16923
Microsoft SQL Server 7.0 SP1 alpha
-
Microsoft S70761a.exe
Alpha
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=16924
Microsoft SQL Server 7.0
-
Microsoft S70761i.exe
Intel
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=16923