SQL 2000 SP3 doesn't apply older fixes in SP1

From: Tom Steger (tsteger@jato.com)
Date: 01/31/03


From: "Tom Steger" <tsteger@jato.com>
Date: Fri, 31 Jan 2003 11:03:54 -0800


After installing SQL 2000 SP3 on a cleanly installed SQL
2000 Standard (no SP) box, and then running the MBSA 1.1
get this output about SQL Server:

*******************************************************

Instance (default): 5 security updates are missing, are
out of date, or could not be confirmed.
Result Details

SQL Server Security Updates
Security updates confirmed as missing are marked with a
red X
Score Security Update Description Reason
 MS00-092 Extended Stored Procedure Parameter Parsing
Vulnerability File g:\MSSQL2000\MSSQL\Binn\ODSOLE70.dll
has a file version [2000.80.194.0] that is less than what
is expected [2000.80.223.0].
 MS01-032 SQL Query Method Enables Cached Administrator
Connection to be Reused File g:\MSSQL2000
\MSSQL\Binn\SQLSERVR.exe has a file version
[2000.80.194.0] that is less than what is expected
[2000.80.296.0].
 MS01-041 Malformed RPC Request Can Cause Service Failure
File g:\MSSQL2000\MSSQL\Binn\SSmsRP70.dll has a file
version [2000.80.194.0] that is less than what is expected
[2000.80.213.0].

Security updates that are out of date are marked with a
yellow X
Score Security Update Description Reason
  The latest service pack for this product is not
installed. The latest service pack for this product is not
installed. Currently SQL Server 2000 Gold is installed.
The latest service pack is SQL Server 2000 SP3.

Security updates that the tool cannot confirm as installed
on the scanned computer are marked with a blue asterisk
Score Security Update Description Reason
 MS02-035 SQL Server Installation Process May Leave
Passwords on System (Q263968) Please refer to Q306460 for
a detailed explanation.
*******************************************************

It appears that Service Pack 3 is breaking some SP1 fixes
for SQL.

Please advise.



Relevant Pages

  • Re: How to install service pack 3a on a failover cluster
    ... The steps for installing service pack 3a is documented in the Readme for service pack 3a. ... The following information applies only to SQL Server 2000 components that are part of a failover cluster. ... If any resources have been added with dependencies on SQL Server resources, those dependencies must either be removed or taken offline before you install SP3a. ...
    (microsoft.public.sqlserver.clustering)
  • Re: SBS Monitoring reinstall fails
    ... -- SharePoint instance on SQL Server 2000 SP4 ... Microsoft Data Engine. ... Rerun Setup, and retry installing ...
    (microsoft.public.windows.server.sbs)
  • Re: Program FilesMicrosoft SQL Server80?
    ... > When installing MSDE onto the d: ... Are theses things needed for MSDE to ... among all instances with different service pack level, ... Andrea Montanari (Microsoft MVP - SQL Server) ...
    (microsoft.public.sqlserver.msde)
  • Re: There was a problem loading data: Generating user instance in SQL Server is disabled.
    ... When I installed VBExpress and C# Express 2008, using the default settings with only one exception it was the path for the installation since there is nothing else than the OS on C: so everything else is on D: ... Yes, I talk SQL Server and SQL Server Express without dsitinguashing them because in most cases, there is not differece in the regards of inexperienced users. ... USER INSTANCE, however, is only available to SQL Server Express. ... Since you have already get it installed into a setting that is not meet the default requirement for those sample apps, you need to learnto reconfigure the system, or you could try to uninstall and then re-install, so you have chance to studybefore installing and configuring your OS to meet the all requirements and to get the installation right. ...
    (microsoft.public.vstudio.general)
  • Re: Reporting Services DISABLES DEFAULT Transaction Isolation Level!!!
    ... installing RS specifically, while I see it without such install. ... Tibor Karaszi, SQL Server MVP ... > Server when run pre- and post- Reporting Services install. ... > It's like the Reporting Services team removed the read committed isolation ...
    (microsoft.public.sqlserver.server)