Vulnerabilities > CVE-2002-0056 - Buffer Overflow vulnerability in Microsoft SQL Server OLE DB Provider Name

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft

Summary

Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Oval

accepted2005-10-19T05:47:00.000-04:00
classvulnerability
contributors
  • nameYi-Fang Koh
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameChristine Walzer
    organizationThe MITRE Corporation
  • nameChristine Walzer
    organizationThe MITRE Corporation
descriptionBuffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.
familywindows
idoval:org.mitre.oval:def:271
statusaccepted
submitted2003-10-10T12:00:00.000-04:00
titleSQL Server OpenDataSource/OpenRowset Buffer Overflow
version3