Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple bugs in Microsoft SQL Server (multiple bugs)
updated since 21.02.2002
Published:17.10.2002
Source:MICROSOFT
SecurityVulns ID:1803
Type:local
Level:6/10
Description:Buffer overflows in OpenDataSource, OPENROWSET, pwdencrypt and xp_dirtree. Weak registry permissions, weak password enbcryption.
Affected:MICROSOFT : SQL Server 7.0
 MICROSOFT : SQL Server 2000
Original documentdocumentDavid Litchfield, Microsoft SQL Server Webtasks privilege upgrade (#NISR17102002) (17.10.2002)
 documentMICROSOFT, Microsoft Security Bulletin MS02-061: Elevation of Privilege in SQL Server Web Tasks (Q316333) (17.10.2002)
 documentMICROSOFT, Security Bulletin MS02-056: Cumulative Patch for SQL Server (Q316333) (03.10.2002)
 documentNGSSoftware Insight Security Research, Microsoft SQL Server Stored procedures [sp_MSSetServerPropertiesn and sp_MSsetalertinfo] (#NISR03092002A) (03.09.2002)
 documentDavid Litchfield, Arbitrary Command Execution on Distributor SQL Server 2000 machines (#NISR22002002A) (23.08.2002)
 documentMark Litchfield, More DBCC overruns SQL SEVER 2000 (22.08.2002)
 documentDavid Litchfield, Microsoft SQL Server Agent Jobs Vulnerabilities (#NISR15002002B) (16.08.2002)
 documentDavid Litchfield, Microsoft SQL Server Extended Stored Procdure privilege upgrade vulnerabilities (#NISR15002002A) (16.08.2002)
 documentMICROSOFT, Security Bulletin MS02-043: Cumulative Patch for SQL Server (Q316333) (16.08.2002)
 documentNGSSoftware Insight Security Research, Microsoft SQL Server 2000,7 OpenRowSet Buffer Overflow vulnerability (#NISR02072002) (05.08.2002)
 documentMICROSOFT, Security Bulletin MS02-040: Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise (Q326573) (03.08.2002)
 documentc c, SQL Server 2000 Buffer Overflows and SQL Inyection vulnerabilities. (26.07.2002)
 documentNGSSoftware Insight Security Research, Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) (25.07.2002)
 documentMICROSOFT, Security Bulletin MS02-038: Cumulative Patch for SQL Server 2000 Service Pack 2 (Q316333) (25.07.2002)
 documentMICROSOFT, Security Bulletin MS02-039: Buffer Overruns in SQL Server 2000 Resolution Service Could Enable Code Execution (Q323875) (25.07.2002)
 documentc c, SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file (11.07.2002)
 documentNGSSoftware Insight Security Research, Microsoft SQL Server 2000 'BULK INSERT' Buffer Overflow (#NISR11072002) (11.07.2002)
 documentMICROSOFT, Security Bulletin MS02-035: SQL Server Installation Process May Leave Passwords on System (Q263968) (11.07.2002)
 documentMICROSOFT, Security Bulletin MS02-034: Cumulative Patch for SQL Server (Q316333) (11.07.2002)
 documentNGSSoftware Insight Security Research, Microsoft SQL Server 2000 OpenDataSource Buffer Overflow (#NISR19062002) (20.06.2002)
 documentmartin rakhmanoff, Microsoft SQL Server 2000 pwdencrypt() buffer overflow (14.06.2002)
 documentMICROSOFT, Security Bulletin MS02-020:SQL Extended Procedure Functions Contain Unchecked Buffers (Q319507) (18.04.2002)
 documentc c, Many, many, many Sql Server 7 & 2000 Buffer Overflows (13.03.2002)
 documentc c, Another Sql Server 7 Buffer Overflow (05.03.2002)
 documentMICROSOFT, Security Bulletin MS02-007 (21.02.2002)
Files:MS SQL Server Hello Overflow NASL script
 MSDE,Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru