PT-2002-1677 · Microsoft · Sql Server Desktop Engine (Msde) 2000+1

Publicado

2002-07-12

·

Atualizado

2018-10-12

·

CVE-2002-0641

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server 2000 Microsoft SQL Server Desktop Engine (MSDE) 2000
Description A buffer overflow issue exists in the bulk insert procedure, allowing attackers with database administration privileges to execute arbitrary code. This can be achieved by using a long filename in the BULK INSERT query.
Recommendations For Microsoft SQL Server 2000, consider restricting database administration privileges to minimize the risk of exploitation. For Microsoft SQL Server Desktop Engine (MSDE) 2000, avoid using long filenames in the BULK INSERT query until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0641

Produtos afetados

Sql Server 2000
Sql Server Desktop Engine (Msde) 2000