PT-2002-1677 · Microsoft · Sql Server Desktop Engine (Msde) 2000+1
Publicado
2002-07-12
·
Atualizado
2018-10-12
·
CVE-2002-0641
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server 2000
Microsoft SQL Server Desktop Engine (MSDE) 2000
Description
A buffer overflow issue exists in the bulk insert procedure, allowing attackers with database administration privileges to execute arbitrary code. This can be achieved by using a long filename in the BULK INSERT query.
Recommendations
For Microsoft SQL Server 2000, consider restricting database administration privileges to minimize the risk of exploitation.
For Microsoft SQL Server Desktop Engine (MSDE) 2000, avoid using long filenames in the BULK INSERT query until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sql Server 2000
Sql Server Desktop Engine (Msde) 2000