The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-039: Buffer Overruns in SQL Server 2000 Resolution Service Could Enable Code Execution (Q323875)
Time: 00:00 EST/05:00 GMT | News Source: ActiveWin.com | Posted By: Robert Stein

SQL Server 2000 introduces the ability to host multiple instances of SQL Server on a single physical machine. Each instance operates for all intents and purposes as though it was a separate server. However, the multiple instances cannot all use the standard SQL Server session port (TCP 1433). While the default instance listens on TCP port 1433, named instances listen on any port assigned to them. The SQL Server Resolution Service, which operates on UDP port 1434, provides a way for clients to query for the appropriate network endpoints to use for a particular SQL Server instance. There are three security vulnerabilities here. The first two are buffer overruns. By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten. Overwriting it with random data would likely result in the failure of the SQL Server service; overwriting it with carefully selected data could allow the attacker to run code in the security context of the SQL Server service.

The third vulnerability is a denial of service vulnerability. SQL uses a keep-alive mechanism to distinguish between active and passive instances. It is possible to create a keep-alive packet that, when sent to the Resolution Service, will cause SQL Server 2000 to respond with the same information. An attacker who created such a packet, spoofed the source address so that it appeared to come from a one SQL Server 2000 system, and sent it to a neighboring SQL Server 2000 system could cause the two systems to enter a never-ending cycle of keep-alive packet exchanges. This would consume resources on both systems, slowing performance considerably.

Write Comment
Return to News

  Displaying 476 through 480 of 480
Prev | First
  The time now is 8:57:28 PM ET.
Any comment problems? E-mail us
#476 By 4240821 (142.252.120.118) at 4/12/2025 3:34:53 PM
https://telegra.ph/Anshul-Learns-Freedom-Through-the-Wind-04-11
https://telegra.ph/Tesla-Model-Y-Adventure-and-Eco-Friendly-Drive-04-11
https://telegra.ph/Tommy-Edmans-Bat-Mystery-Solved-04-12
https://telegra.ph/Senate-Passes-Permanent-Daylight-Saving-Time-04-11
https://telegra.ph/1400-Stimulus-Checks-Approved-in-Relief-Bill-04-09
https://telegra.ph/Anshul-Kamboj-Vanished-into-Thin-Air-04-11
https://telegra.ph/Mystery-and-Magic-at-Augusta-National-04-09
https://telegra.ph/SolarMax-Greed-Fraud-and-Tragic-Losses-04-10
https://telegra.ph/Pirates-Triumph-Over-Reds-in-Sea-Battle-04-12
https://telegra.ph/Liams-Dream-of-Mars-Rocket-Launch-04-09

#477 By 4240821 (193.232.144.239) at 4/13/2025 10:33:16 AM
https://telegra.ph/NBA-Standings-Mystery-Collusion-or-Chaos-04-12
https://telegra.ph/Green-Jacket-Heist-at-Masters-2025-04-10
https://telegra.ph/2024-Masters-Tournament-Standings-Summary-04-10
https://telegra.ph/Betis-Triumphs-Over-Jagiellonia-in-Europa-League-04-10
https://telegra.ph/Al-Nassr-vs-Al-Riyadh-Drama-Filled-Clash-04-12
https://telegra.ph/Boston-Weather-Chaos-From-Snow-to-Heatwave-04-12
https://telegra.ph/Mini-Crossword-Leads-to-Hidden-Treasure-Hunt-04-11
https://telegra.ph/LeBron-James-Suffers-Severe-Hamstring-Injury-04-12-2
https://telegra.ph/Phillies-Miracle-Season-Ends-in-World-Series-04-10
https://telegra.ph/Amateur-Nick-Dunlap-Wins-PGA-Tour-Event-04-10

#478 By 4240821 (193.232.144.239) at 4/14/2025 11:58:38 AM
https://telegra.ph/Barcelona-Edges-Out-Leganés-in-Late-Drama-04-12
https://telegra.ph/Local-Artist-Lucy-Markovics-Abstract-Paintings-Gain-Recognition-04-11
https://telegra.ph/Tommy-Edman-Becomes-First-Korean-American-to-Hit-for-the-Cycle-04-12
https://telegra.ph/Gustavo-Dudamel-Inspires-Music-for-All-04-13
https://telegra.ph/Jon-Bon-Jovi-Opens-New-Homeless-Shelter-04-12-2
https://telegra.ph/Bucks-Pistons-Rivalry-Heats-Up-in-Playoffs-04-11
https://telegra.ph/Siemens-CEOs-Bold-Green-Tech-Bet-04-11
https://telegra.ph/Marsai-Martin-Secures-Historic-Netflix-Deal-04-11
https://telegra.ph/Rockets-Edge-Lakers-in-Thrilling-Showdown-04-12
https://telegra.ph/Tommy-Fleetwood-Claims-Maiden-PGA-Tour-Victory-04-12

#479 By 4240821 (142.252.120.118) at 4/15/2025 12:39:04 AM
https://telegra.ph/Belal-Muhammads-Unbreakable-Fighting-Spirit-04-13
https://telegra.ph/Lady-Gagas-Spectacular-Tour-Experience-04-12
https://telegra.ph/El-Salvador-Plans-Bitcoin-City-Amid-Economic-Growth-04-14
https://telegra.ph/Pakistan-Women-vs-West-Indies-Women-Stats-04-14
https://telegra.ph/Oldest-Masters-Winner-Defies-Age-04-13
https://telegra.ph/Bronny-James-Breaks-Free-from-Fathers-Shadow-04-12
https://telegra.ph/Pete-Alonso-Dominates-Mets-Early-Season-04-12
https://telegra.ph/Samsunspor-vs-Galatasaray-Football-Match-Overview-04-11
https://telegra.ph/Wizards-Edge-Heat-in-Overtime-Thriller-04-13
https://telegra.ph/Ludvig-Ã…bergs-Rising-Golf-Career-Highlights-04-12

#480 By 4240821 (46.232.37.254) at 4/15/2025 1:58:21 PM
https://telegra.ph/Pennsylvania-Governors-Residence-Fire-Facts-04-13
https://telegra.ph/Masters-TV-Coverage-Sparks-Fan-Outrage-04-12
https://telegra.ph/Immigration-Lawyer-Deported-Ethical-Dilemma-04-14
https://telegra.ph/HBO-Reveals-Harry-Potter-Series-Cast-04-14
https://telegra.ph/Trumps-Over-the-Top-Easter-Egg-Roll-04-13
https://telegra.ph/WNBA-Draft-2024-Historic-Picks-and-Surprises-04-15
https://telegra.ph/12th-Man-Dreams-Come-True-04-12
https://telegra.ph/Michael-Rookers-Fun-and-Spicy-Facts-04-14
https://telegra.ph/Explosive-Secrets-of-Oklahoma-City-Bombing-04-14
https://telegra.ph/Bernhard-Langer-Sets-Senior-Golf-Record-04-13

Write Comment
Return to News
  Displaying 476 through 480 of 480
Prev | First
  The time now is 8:57:28 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *