The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-007: SQL Server Remote Data Source Function Contain Unchecked Buffers
Time: 13:01 EST/18:01 GMT | News Source: Microsoft TechNet Security | Posted By: Robert Stein

One of the features of Structured Query Language (SQL) in SQL Server 7.0 and 2000 is the ability to connect to remote data sources. One capability of this feature is the ability to use “ad hoc” connections to connect to remote data sources without setting up a linked server for less-often used data-sources. This is made possible through the use of OLE DB providers, which are low-level data source providers. This capability is made possible by invoking the OLE DB provider directly by name in a query to connect to the remote data source.

An unchecked buffer exists in the handling of OLE DB provider names in ad hoc connections. A buffer overrun could occur as a result and could be used to either cause the SQL Server service to fail, or to cause code to run in the security context of the SQL Server. SQL Server can be configured to run in various security contexts, and by default runs as a domain user. The precise privileges the attacker could gain would depend on the specific security context that the service runs in.

Write Comment
Return to News

  Displaying 426 through 427 of 427
Prev | First
  The time now is 8:46:09 AM ET.
Any comment problems? E-mail us
#426 By 4240821 (142.111.253.203) at 1/29/2025 8:21:28 AM
https://justpaste.me/Xs8k
https://justpaste.me/XorG2
https://justpaste.me/Xs4x
https://justpaste.me/XW4y1
https://justpaste.me/XNrQ1
https://justpaste.me/Xx4G
https://justpaste.me/XfTr1
https://justpaste.me/Xyv72
https://justpaste.me/XkBD3
https://justpaste.me/XYxM2

#427 By 4240821 (193.36.231.79) at 1/30/2025 1:56:41 PM
https://justpaste.me/XlzA1
https://justpaste.me/XWsx1
https://justpaste.me/XwUQ
https://justpaste.me/XhUT7
https://justpaste.me/XVfo
https://justpaste.me/Y37e
https://justpaste.me/XeUc5
https://justpaste.me/Xrk72
https://justpaste.me/Y0fk3
https://justpaste.me/Xxdt1

Write Comment
Return to News
  Displaying 426 through 427 of 427
Prev | First
  The time now is 8:46:09 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *