Microsoft SQL Server / MSDE Multiple Vulnerabilities
BID:8261
Info
Microsoft SQL Server / MSDE Multiple Vulnerabilities
| Bugtraq ID: | 8261 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 23 2003 12:00AM |
| Credit: | Discovery is credited to Andreas Junstream of @Stake. |
| Vulnerable: |
Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP3a Microsoft SQL Server 2000 SP3 Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server / MSDE Multiple Vulnerabilities
Microsoft SQL Server and the Microsoft Data Engine have been reported to be prone to three vulnerabilities.
The first issue could allow an attacker to hijack a named pipe. This could allow the attacker to gain control of a named pipe to which a legitimate user has authenticated. This could allow a local attacker to gain the privilege level of the authenticated user.
The second issue could allow any local or remote user, who can authenticate (Everyone Group), to the SQL Server to cause a denial of service. If the attacker sends an unusually large request to a named pipe, the SQL Server will become unresponsive. The server may have to be rebooted to restore normal operations.
The third issue is a buffer overflow vulnerability. This issue could allow an attacker that is authenticated to the SQL Server to elevate their privilege level.
This BID will be separated into multiple records after complete analysis of each issue. At that time this record will be retired.
Microsoft SQL Server and the Microsoft Data Engine have been reported to be prone to three vulnerabilities.
The first issue could allow an attacker to hijack a named pipe. This could allow the attacker to gain control of a named pipe to which a legitimate user has authenticated. This could allow a local attacker to gain the privilege level of the authenticated user.
The second issue could allow any local or remote user, who can authenticate (Everyone Group), to the SQL Server to cause a denial of service. If the attacker sends an unusually large request to a named pipe, the SQL Server will become unresponsive. The server may have to be rebooted to restore normal operations.
The third issue is a buffer overflow vulnerability. This issue could allow an attacker that is authenticated to the SQL Server to elevate their privilege level.
This BID will be separated into multiple records after complete analysis of each issue. At that time this record will be retired.
Exploit / POC
Microsoft SQL Server / MSDE Multiple Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SQL Server / MSDE Multiple Vulnerabilities
Solution:
Microsoft has released fixes:
Microsoft SQL Server 2000 SP3
Microsoft Data Engine (MSDE) 1.0
Microsoft SQL Server 2000 Desktop Engine
Microsoft SQL Server 7.0 SP4
Microsoft SQL Server 2000 SP3a
Solution:
Microsoft has released fixes:
Microsoft SQL Server 2000 SP3
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8 6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C 5-ADD3-B8C99618E68D&displaylang=en
Microsoft Data Engine (MSDE) 1.0
-
Microsoft SQL70-KB815495-v7.00.1094-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=FE5B0892-A5C9-44C 2-9B42-0D291E9C1636&displaylang=en
Microsoft SQL Server 2000 Desktop Engine
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8 6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C 5-ADD3-B8C99618E68D&displaylang=en
Microsoft SQL Server 7.0 SP4
-
Microsoft SQL70-KB815495-v7.00.1094-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=FE5B0892-A5C9-44C 2-9B42-0D291E9C1636&displaylang=en
Microsoft SQL Server 2000 SP3a
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8 6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exe
SQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C 5-ADD3-B8C99618E68D&displaylang=en
References
Microsoft SQL Server / MSDE Multiple Vulnerabilities
References:
References:
- Microsoft Security Bulletin MS03-031 (Microsoft)
- Microsoft SQL Server DoS (@stake)
- Microsoft SQL Server DoS ("@stake Advisories"
) - Microsoft SQL Server local code execution ("@stake Advisories"
)