Re: Public announcements of SQL Security Vulnerabilities

From: Mary Chipman (mchip@nomail.please)
Date: 07/27/02


From: Mary Chipman <mchip@nomail.please>
Date: Sat, 27 Jul 2002 09:14:35 -0400


On Fri, 26 Jul 2002 16:06:52 -0600, "Chris Wood"
<chris.wood@gov.ab.ca> wrote:

>Whilst I feel it is helpful, because I can now fully understand the
>vulnerability, it is putting some pressure on me to make a hasty decision
>about implementing the security patch. It can give little time for testing
>any SQL application, that might be affected, before it MUST be implemented
>in the Production environment.

What choice do you have? Don't implement the patch and leave the
server vulnerable, hoping for the best? Only you know your environment
and only you can weigh the likelihood of a particular attack against
the possibility of a bad patch bringing down the production server.

-- Mary
MCW Technologies
http://www.mcwtech.com



Relevant Pages

  • Re: Download.ject - commentary - LONG
    ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
    (microsoft.public.win2000.security)
  • Vulnerability Details for MS02-012
    ... Microsoft released a patch for a denial of service ... vulnerability in the Windows 2000 SMTP component. ... This bug affects all Windows 2000 systems running the SMTP service that have ...
    (Bugtraq)
  • Microsoft Security Bulletin MS01-044
    ... Subject: Microsoft Security Bulletin MS01-044 ... 15 August 2001 Cumulative Patch for IIS ... - A denial of service vulnerability that could enable an attacker ...
    (Bugtraq)
  • [NT] 15 August 2001 Cumulative Patch for IIS
    ... Microsoft has released an important patch for IIS administrators. ... * A denial of service vulnerability that could enable an attacker to ...
    (Securiteam)
  • McAfee ePolicy Orchestrator Format String Vulnerability (a031703-1)
    ... ePolicy Orchestrator Format String Vulnerability ... on the host they wish to compromise. ... The vendor has made a patch available. ...
    (Bugtraq)