PT-2008-1761 · Microsoft · Sql Server 2005 Sp2+4
Published
2008-07-08
·
Updated
2018-10-15
·
CVE-2008-0106
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server 2005 SP1
Microsoft SQL Server 2005 SP2
Microsoft SQL Server 2005 Express Edition SP1
Microsoft SQL Server 2005 Express Edition SP2
Description
A buffer overflow issue exists, allowing remote authenticated users to execute arbitrary code via a crafted insert statement. This could enable an authenticated attacker to gain elevation of privilege, potentially running code and taking complete control of the system.
Recommendations
For Microsoft SQL Server 2005 SP1, update to a version that includes the fix for this issue.
For Microsoft SQL Server 2005 SP2, update to a version that includes the fix for this issue.
For Microsoft SQL Server 2005 Express Edition SP1, update to a version that includes the fix for this issue.
For Microsoft SQL Server 2005 Express Edition SP2, update to a version that includes the fix for this issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sql Server 2005 Express Edition Sp1
Sql Server 2005 Express Edition Sp2
Sql Server 2005 Sp1
Sql Server 2005 Sp2
Sql Server