The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-060: SQL Server Text Formatting Functions Contain unchecked Buffers
Time: 05:31 EST/10:31 GMT | News Source: Microsoft TechNet Security | Posted By: Matthew Sabean

SQL Server 7.0 and 2000 provide a number of functions that enable database queries to generate text messages. In some cases, the functions create a text message and store it in a variable; in others, the functions directly display the message. Two vulnerabilities associated with these functions have been discovered.

The first vulnerability results because of a flaw in the functions themselves. Several of the functions don't adequately verify that the requested text will fit into the buffer that's supplied to hold it. A buffer overrun could occur as a result, and could be used either to run code in the security context of the SQL Server service or to cause the SQL Server service to fail. SQL Server can be configured to run in various security contexts, and by default runs as a domain user. The precise privileges the attacker could gain would depend on the specific security context that the service runs in.

The second vulnerability results because of a format string vulnerability in the C runtime functions that the SQL Server functions call when installed on Windows NT(r) 4.0, Windows(r) 2000 or Windows XP. Although format string vulnerabilities often can be exploited to run code of the attacker's choice, that is not true in this case. Because of the specific way this vulnerability occurs, the C Runtime code would always be overrun with the same values regardless of the attacker's inputs. As a result, this vulnerability could only be used as a denial of service.

Write Comment
Return to News

  Displaying 776 through 781 of 781
Prev | First
  The time now is 5:26:54 PM ET.
Any comment problems? E-mail us
#776 By 4240821 (82.115.4.100) at 1/10/2026 1:03:48 PM
https://www.pillowfort.social/posts/6440301
https://www.pillowfort.social/posts/6440215
https://www.pillowfort.social/posts/6440119
https://www.pillowfort.social/posts/6439967
https://www.pillowfort.social/posts/6439868
https://www.pillowfort.social/posts/6439705
https://www.pillowfort.social/posts/6439345
https://www.pillowfort.social/posts/6439118
https://www.pillowfort.social/posts/6438908
https://www.pillowfort.social/posts/6438758

#777 By 4240821 (193.39.208.35) at 1/10/2026 6:24:02 PM
https://www.pillowfort.social/posts/6637501
https://www.pillowfort.social/posts/6637257
https://www.pillowfort.social/posts/6637096
https://www.pillowfort.social/posts/6636983
https://www.pillowfort.social/posts/6636876
https://www.pillowfort.social/posts/6636622
https://www.pillowfort.social/posts/6636469
https://www.pillowfort.social/posts/6636408
https://www.pillowfort.social/posts/6636223
https://www.pillowfort.social/posts/6636121

#778 By 4240821 (193.39.208.35) at 1/10/2026 7:47:41 PM
https://www.pillowfort.social/posts/7092948
https://www.pillowfort.social/posts/7092881
https://www.pillowfort.social/posts/7092786
https://www.pillowfort.social/posts/7092756
https://www.pillowfort.social/posts/7092727
https://www.pillowfort.social/posts/7092686
https://www.pillowfort.social/posts/7092620
https://www.pillowfort.social/posts/7092543
https://www.pillowfort.social/posts/7092492
https://www.pillowfort.social/posts/7092415

#779 By 4240821 (193.39.208.35) at 1/11/2026 4:52:38 AM
https://www.pillowfort.social/posts/6787283
https://www.pillowfort.social/posts/6787143
https://www.pillowfort.social/posts/6786964
https://www.pillowfort.social/posts/6786796
https://www.pillowfort.social/posts/6786551
https://www.pillowfort.social/posts/6786477
https://www.pillowfort.social/posts/6786409
https://www.pillowfort.social/posts/6786369
https://www.pillowfort.social/posts/6786273
https://www.pillowfort.social/posts/6786203

#780 By 4240821 (193.39.208.35) at 1/11/2026 9:33:50 AM
https://www.pillowfort.social/posts/6845585
https://www.pillowfort.social/posts/6845525
https://www.pillowfort.social/posts/6845453
https://www.pillowfort.social/posts/6844975
https://www.pillowfort.social/posts/6844839
https://www.pillowfort.social/posts/6844680
https://www.pillowfort.social/posts/6844522
https://www.pillowfort.social/posts/6844394
https://www.pillowfort.social/posts/6844189
https://www.pillowfort.social/posts/6843999

#781 By 4240821 (82.115.4.230) at 1/11/2026 2:41:17 PM
https://www.pillowfort.social/posts/6501013
https://www.pillowfort.social/posts/6500830
https://www.pillowfort.social/posts/6500664
https://www.pillowfort.social/posts/6500533
https://www.pillowfort.social/posts/6500395
https://www.pillowfort.social/posts/6500246
https://www.pillowfort.social/posts/6500073
https://www.pillowfort.social/posts/6500034
https://www.pillowfort.social/posts/6499977
https://www.pillowfort.social/posts/6499905

Write Comment
Return to News
  Displaying 776 through 781 of 781
Prev | First
  The time now is 5:26:54 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *