Microsoft Security Bulletin MS02-038

Q316333 · Windows - Bởi Microsoft

· 25/08/2008 18:56 (16 năm trước)

Giới Thiệu · Microsoft Security Bulletin MS02-038

This patch eliminates two newly discovered vulnerabilities affecting SQL Server 2000 and MSDE 2000:
  • A buffer overrun vulnerability that occurs in several Database Consistency Checkers (DBCCs) that ship as part of SQL Server 2000. DBCCs are command console utilities that allow maintenance and other operations to be performed on a SQL Server. While many of these are executable only by sysadmin, some are executable by members of the db_owner and db_ddladmin roles as well. In the most serious case, exploiting this vulnerability would enable an attacker to run code in the context of the SQL Server service, thereby giving the attacker complete control over all databases on the server.
  • A SQL injection vulnerability that occurs in two stored procedures used in database replication. One of these can only be run by users who have been assigned the db_owner role; the other, due to a permissions error, could be run by any user who could log onto the server interactively. Exploiting the vulnerability could enable an attacker to run operating system commands on the server, but is subject to significant mitigating factors as discussed below.

Full Specifications · Google Chrome Zing MP3

Phiên bản Q316333
Cập nhật 25/08/2008 (16 năm trước)
Nhà phát triển Microsoft
Thể loại Developer Tools
Hệ điều hành Windows
Hệ điều hành cài đặt Windows , Windows 2000
Yêu cầu
  • Microsoft SQL Server 2000.
  • Microsoft Desktop Engine (MSDE) 2000
  • Lượt tải về 371,767

    Phần mềm ứng dụng cùng danh mục

    Bình luận