Vulnerabilities > CVE-2002-1137 - Buffer Overflow vulnerability in Microsoft Data Engine and SQL Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family | Databases |
NASL id | MSSQL_LITCHFIELD_OVERFLOWS.NASL |
description | The remote MS SQL server is affected by several overflows that could be exploited by an attacker to gain SYSTEM access on that host. Note that a worm (sapphire) is exploiting these vulnerabilities in the wild. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11214 |
published | 2003-01-25 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11214 |
title | MS02-061: Microsoft SQL Server Multiple Vulnerabilities (uncredentialed check) |
code |
|
References
- http://www.ciac.org/ciac/bulletins/n-003.shtml
- http://www.cisco.com/warp/public/707/cisco-sa-20030126-ms02-061.shtml
- http://www.scan-associates.net/papers/foxpro.txt
- http://www.securityfocus.com/bid/5877
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10255