Reported April 18, 2002, by
Microsoft.
VERSIONS AFFECTED
·
Microsoft SQL Server 7.0
·
Microsoft SQL Server 2000
DESCRIPTION
An unchecked buffer exists in
several of the extended store procedures that Microsoft shipped with SQL Server
7.0 and SQL Server 2000. An attacker can exploit this vulnerability to cause
the SQL Server service to fail or to run code in the security context in which
SQL Server is running.
VENDOR RESPONSE
The
vendor, Microsoft, has released
security bulletin MS02-020,
which addresses this vulnerability, and recommends that affected users apply
the appropriate patch listed at this URL.
CREDIT
Discovered by Microsoft.