PT-2002-1685 · Microsoft · Sql Server 2000
Published
2002-08-12
·
Updated
2018-10-12
·
CVE-2002-0650
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server 2000
Description
The issue allows remote attackers to cause a denial of service, specifically bandwidth consumption, by sending a "ping" style packet to the Resolution Service on UDP port 1434 with a spoofed IP address of another SQL Server system. This action causes the two servers to exchange packets in an infinite loop.
Recommendations
For Microsoft SQL Server 2000, consider restricting access to the Resolution Service on UDP port 1434 to prevent spoofed packets from initiating the denial of service. As a temporary workaround, consider implementing firewall rules to block unsolicited UDP traffic on port 1434.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sql Server 2000