This is a cumulative patch that includes the functionality of all
previously released patches for SQL Server 2000. In addition, it
eliminates three newly discovered vulnerabilities affecting SQL
Server 2000 and MSDE 2000 (but not any previous versions of SQL
Server or MSDE):
- - A buffer overrun vulnerability in a procedure used to encrypt SQL
Server credential information. An attacker who was able to
successfully exploit this vulnerability could gain significant
control over the database and possibly the server itself depending
on the account SQL server runs as.
- - A buffer overrun vulnerability in a procedure that relates to the
bulk inserting of data in SQL Server tables. An attacker who was
able to successfully exploit this vulnerability could gain
significant control over the database and possibly the server
itself.
- - A privilege elevation vulnerability that results because of in-
correct permissions on the Registry key that stores the SQL Server
service account information. An attacker who was able to success-
fully exploit this vulnerability could gain greater privileges on
the system than had been granted by the system administrator --
potentially even the same rights as the operating system.
Download locations for this patch
Microsoft SQL Server 2000:
http://support.microsoft.com/support/misc/kblookup.asp?id=Q316333
|