MS02-039: buffer overruns in Structured Query Language Server 2000 resolution service could enable code execution. (Microsoft: security alerts and advisories issued).(Brief Article)(Product Announcement)

Information Systems Auditor, September, 2002

Issue

Structured Query Language (SQL) Server 2000 introduces the ability to host multiple instances on a single physical machine. Each instance operates for all intents and purposes as though it was a separate server. However, the multiple instances cannot all use the standard SQL Server session port-transmission control protocol (TCP) port 1433). While the default instance listens on TCP port 1433, named instances listen on any port assigned to them. The SQL Server Resolution Service, which operates on UDP port 1434, provides a way for clients to query for the appropriate network endpoints to use for a particular SQL Server instance.

There are three security vulnerabilities here. The first two are buffer overruns. By sending a carefully crafted...

Premium Content Partnership | HighBeam Research provides an in-depth online archive library of reference works. HighBeam Research

 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
advertisement
  • Click Here
  • Click Here
  • Click Here
advertisement