Vulnerabilities > CVE-2002-0624 - Unspecified vulnerability in Microsoft Msde and SQL Server

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Exploit-Db

descriptionMicrosoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability. CVE-2002-0624. Local exploit for windows platform
idEDB-ID:21549
last seen2016-02-02
modified2002-06-14
published2002-06-14
reporterMartin Rakhmanoff
sourcehttps://www.exploit-db.com/download/21549/
titleMicrosoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability

Oval

accepted2014-06-23T04:07:46.400-04:00
classvulnerability
contributors
  • nameYi-Fang Koh
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameIngrid Skoog
    organizationThe MITRE Corporation
  • nameJerome Athias
    organizationMcAfee, Inc.
descriptionBuffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
familywindows
idoval:org.mitre.oval:def:291
statusaccepted
submitted2003-10-10T12:00:00.000-04:00
titleUnchecked Buffer in Password Encryption Procedure
version4