Vulnerabilities > CVE-2002-0650 - Unspecified vulnerability in Microsoft SQL Server 2000
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Databases |
NASL id | MSSQL_LITCHFIELD_OVERFLOWS.NASL |
description | The remote MS SQL server is affected by several overflows that could be exploited by an attacker to gain SYSTEM access on that host. Note that a worm (sapphire) is exploiting these vulnerabilities in the wild. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11214 |
published | 2003-01-25 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11214 |
title | MS02-061: Microsoft SQL Server Multiple Vulnerabilities (uncredentialed check) |
code |
|
References
- http://marc.info/?l=bugtraq&m=102760196931518&w=2
- http://marc.info/?l=bugtraq&m=102760196931518&w=2
- http://marc.info/?l=ntbugtraq&m=102760479902411&w=2
- http://marc.info/?l=ntbugtraq&m=102760479902411&w=2
- http://www.iss.net/security_center/static/9662.php
- http://www.iss.net/security_center/static/9662.php
- http://www.osvdb.org/878
- http://www.osvdb.org/878
- http://www.securityfocus.com/bid/5312
- http://www.securityfocus.com/bid/5312
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039