Re: sp_replwritetovarbin memory overwrite Security threat



Joe,

if they are serious about this I would expect a Security Advisory to appear
here http://www.microsoft.com/technet/security/advisory/default.mspx as the
problem has been publically announced.

Chris

"jaylou" <jaylou@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F45651D0-4A16-4089-A060-CCEA823F1E20@xxxxxxxxxxxxxxxx
Yes I did. Do you know anything about this? I haven't been able to find
much more then more articles pointing back to this alert.

"Chris Wood" wrote:

Joe,

You saw this alert
http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovarbin_memwrite.txt
right?

Chris

"jaylou" <jaylou@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AF1766C1-5F1D-4D8B-A967-F39BBB3D3B2B@xxxxxxxxxxxxxxxx
I recieved an email about this procedure sp_replwritetovarbin. one
recomendation is to remove it from your system.

Does anyone know what this proc is for and what will break if removed?

Also does anyone know if this is a real threat?

TIA,
Joe





.



Relevant Pages

  • Re: sp_replwritetovarbin memory overwrite Security threat
    ... "Chris Wood" wrote: ... if they are serious about this I would expect a Security Advisory to appear ... much more then more articles pointing back to this alert. ... Also does anyone know if this is a real threat? ...
    (microsoft.public.sqlserver.security)
  • Re: sp_replwritetovarbin memory overwrite Security threat
    ... "Chris Wood" wrote: ... if they are serious about this I would expect a Security Advisory to ... much more then more articles pointing back to this alert. ...
    (microsoft.public.sqlserver.security)
  • Re: sp_replwritetovarbin memory overwrite Security threat
    ... Microsoft issued a security advisory, as expected, and it mentions that they ... "Chris Wood" wrote: ... is announced in these builds when the January patches are announced. ... much more then more articles pointing back to this alert. ...
    (microsoft.public.sqlserver.security)
  • Re: sp_replwritetovarbin memory overwrite Security threat
    ... You saw this alert ... recomendation is to remove it from your system. ... Does anyone know what this proc is for and what will break if removed? ... Joe ...
    (microsoft.public.sqlserver.security)

Quantcast