PT-2002-1685 · Microsoft · Sql Server 2000

Published

2002-08-12

·

Updated

2018-10-12

·

CVE-2002-0650

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server 2000
Description The issue allows remote attackers to cause a denial of service, specifically bandwidth consumption, by sending a "ping" style packet to the Resolution Service on UDP port 1434 with a spoofed IP address of another SQL Server system. This action causes the two servers to exchange packets in an infinite loop.
Recommendations For Microsoft SQL Server 2000, consider restricting access to the Resolution Service on UDP port 1434 to prevent spoofed packets from initiating the denial of service. As a temporary workaround, consider implementing firewall rules to block unsolicited UDP traffic on port 1434.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0650

Affected Products

Sql Server 2000