Re: MS SQL Server 2000 SP2 AV problem with pwdencrypt: possible buffer overflow

From: Neil Pike (neilpike@compuserve.com)
Date: 06/18/02


Date: Tue, 18 Jun 2002 10:42:27 +0100
From: Neil Pike <neilpike@compuserve.com>


 Jimmers - I meant "nasty bug" - sorry if you read it any other way.
 
> MS SQL Server 7 is not affected by this vulnerability.
> Also I'm not sure what You'd like to say by 'Jimmers -
> nasty!'. If someone blames me for disclosure of this bug I
> should say that I've reported it one year ago to MS
> support and got no reply. Enough time to wait.

 Neil Pike MVP/MCSE. Protech Computing Ltd
 Reply here - no email
 SQL FAQ (484 entries) see
 http://forumsb.compuserve.com/gvforums/UK/default.asp?SRV=MSDevApps
 (faqxxx.zip in lib 7)
 or www.ntfaq.com/Articles/Index.cfm?DepartmentID=800
 or www.sqlserverfaq.com
 or www.mssqlserver.com/faq



Relevant Pages

  • [NT] SQL Server 2000 Buffer Overflows and SQL Injection Vulnerabilities
    ... allow maintenance and other operations to be performed on a SQL Server, ... fixed database role can run this command. ... Buffer Overrun Vulnerability in Database Consistency Checkers: ... privileges, and only should be granted to trusted users. ...
    (Securiteam)
  • [NT] Cumulative Patch for SQL Server
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... released patches for SQL Server 2000. ... * A buffer overrun vulnerability in a procedure used to encrypt SQL ... An attacker who was able to successfully ...
    (Securiteam)
  • [NT] Another Cumulative Patch for SQL Server Released
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... previously released patches for SQL Server 7.0, SQL Server 2000, and ... malformed login request to an affected server, an attacker could either ... * A buffer overrun vulnerability that occurs in one of the Database ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #96
    ... MICROSOFT VULNERABILITY SUMMARY ... W3C Jigsaw Device Name Path Disclosure Vulnerability ... Microsoft SQL Server 2000 Incorrect Registry Key Permissions... ... Mirabilis ICQ Sound Scheme Remote Configuration Modification Vulnerability ...
    (Focus-Microsoft)
  • [NT] SQL Server Text Formatting Functions Suffer from Buffer Overflows
    ... SQL Server 7.0 and 2000 provide a number of functions that enable database ... The second vulnerability results because of a format string vulnerability ... installed on Windows NT 4.0, Windows 2000, or Windows XP. ... An attacker could exploit the vulnerabilities in either of two ways. ...
    (Securiteam)