MS02-038: cumulative patch for Structured Query Language Server 2000 service pack 2. (Microsoft: security alerts and advisories issued).(Brief Article)(Product Announcement)

Information Systems Auditor, September, 2002

Issue

This patch eliminates two newly discovered vulnerabilities affecting Structured Query Language (SQL) Server 2000 and MSDE 2000:

* a buffer overrun vulnerability that occurs in several database consistency checkers (DBCCs) that ship as part of SQL Server 2000. DBCCs are command console utilities that allow maintenance and other operations to be performed on a SQL Server. While many of these are executable only by sysadmin, some are executable by members of the db owner and db ddladmin roles as well In the most serious case, exploiting this vulnerability would enable attackers to run code in the context of the SQL Server service, thereby giving them complete control over all databases on the server;

* an SQL injection vulnerability that...

Premium Content Partnership | HighBeam Research provides an in-depth online archive library of reference works. HighBeam Research
 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
advertisement
  • Click Here
  • Click Here
  • Click Here
advertisement
Click Here