vendor:
SQL Server 2000
by:
hdm
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: SQL Server 2000
Affected Version From: MSSQL 2000 / MSDE <= SP2
Affected Version To: MSSQL 2000 / MSDE <= SP2
Patch Exists: YES
Related CWE: CVE-2002-0649, OSVDB-4578, BID-5310, MSB-MS02-039
CPE: a:microsoft:sql_server:2000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Microsoft SQL Server Resolution Overflow
This is an exploit for the SQL Server 2000 resolution service buffer overflow. This overflow is triggered by sending a udp packet to port 1434 which starts with 0x04 and is followed by long string terminating with a colon and a number. This module should work against any vulnerable SQL Server 2000 or MSDE install (pre-SP3).
Mitigation:
Install the latest security patches for the SQL Server 2000 or MSDE install