Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
BID:8274
Info
Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
| Bugtraq ID: | 8274 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0231 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to Andreas Junstream of @Stake. |
| Vulnerable: |
Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP3a Microsoft SQL Server 2000 SP3 Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
Microsoft SQL Server and the Microsoft Data Engine have been reported prone to a denial of service attack.
Any local or remote user, who can authenticate and is part of the Everyone Group, may trigger a denial of service condition in an affected SQL Server.
It has been reported that, if a remote attacker sends an unusually large request to a named pipe, the SQL Server will become unresponsive.
Microsoft SQL Server and the Microsoft Data Engine have been reported prone to a denial of service attack.
Any local or remote user, who can authenticate and is part of the Everyone Group, may trigger a denial of service condition in an affected SQL Server.
It has been reported that, if a remote attacker sends an unusually large request to a named pipe, the SQL Server will become unresponsive.
Exploit / POC
Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
References
Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS03-031 (Microsoft)
- Microsoft SQL Server DoS (@stake)
- SQL Server/MSDE-Based Applications (sqlsecurity.com)
- Microsoft SQL Server DoS ("@stake Advisories"
)