Version: 2008
advertisement
Click Here

Microsoft Security Bulletin MS02-039 Q323875

  • Quick specs
  • Price: Update
  • Operating system:
  • Date added: July 24, 2002
  • Total Downloads: 111
  • Downloads last week: 1
  • See full specifications
Add to my list Add to my Watch List
Download Now (159.18K)
Tested spyware free

Publisher's description

From Microsoft :

SQL Server 2000 introduces the ability to host multiple instances of SQL Server on a single physical machine. Each instance operates for all intents and purposes as though it was a separate server. However, the multiple instances cannot all use the standard SQL Server session port (TCP 1433). While the default instance listens on TCP port 1433, named instances listen on any port assigned to them. The SQL Server Resolution Service, which operates on UDP port 1434, provides a way for clients to query for the appropriate network endpoints to use for a particular SQL Server instance. There are three security vulnerabilities here. The first two are buffer overruns. By sending a carefully crafted packet to the Resolution Service, an attacker could cause portions of system memory (the heap in one case, the stack in the other) to be overwritten. Overwriting it with random data would likely result in the failure of the SQL Server service; overwriting it with carefully selected data could allow the attacker to run code in the security context of the SQL Server service. The third vulnerability is a denial of service vulnerability. SQL uses a keep-alive mechanism to distinguish between active and passive instances. It is possible to create a keep-alive packet that, when sent to the Resolution Service, will cause SQL Server 2000 to respond with the same information. An attacker who created such a packet, spoofed the source address so that it appeared to come from a one SQL Server 2000 system, and sent it to a neighboring SQL Server 2000 system could cause the two systems to enter a never-ending cycle of keep-alive packet exchanges. This would consume resources on both systems, slowing performance considerably. Mitigating factors: Buffer Overruns in SQL Server Resolution Service:

  • SQL Server 2000 runs in a security context chosen by the administrator at installation time. By default, it runs as a Domain User. Thus, although the attacker?s code could take any desired action on the database, it would not necessarily have significant privileges at the operating system level if best practices have been followed.
  • The risk posed by the vulnerability could be mitigated by, if feasible, blocking port 1434 at the firewall.
Denial of Service via SQL Server Resolution Service:
  • An attack could be broken off by restarting the SQL Server 2000 service on either of the affected systems. Normal processing on both systems would resume once the attack ceased.
  • The vulnerability provides no way to gain any privileges on the system. It is a denial of service vulnerability only.

Restrict user's ability to run or install any executable program.

More popular Database Software downloads

  1. 4,833 downloads 1. Navicat Lite
  2. 3,021 downloads 2. Navicat Premium
  3. 943 downloads 3. Crystal Reports Server
  4. 722 downloads 4. Crystal Reports
  5. 662 downloads 5. Navicat (MySQL GUI)
  6. See all Database Software downloads
If your BlackBerry is missing these essential apps, you're missing out.

User reviews

Write your own review Be the first one to review Microsoft Security Bulletin MS02-039 Q323875 and share your experience with the CNET community!

Submit your review

Log in or create an account to submit your review for:

Microsoft Security Bulletin MS02-039 Q323875

ORLog in with your Facebook account
1. Rate this product:
(Mouse over the stars to rate this product and click to set your rating.)
2. One-line summary:(Summarize your review in one line. 10 characters minimum; required.)
0 of 55 characters
3. Pros:(Tell us what you like about this product. 10 characters minimum; required.)
0 of 250 characters
4. Cons:(Tell us what you don't like about this product. 10 characters minimum; required.)
0 of 250 characters
Bottom-line summary:(Explain to us in detail why you like or dislike the product, focusing your comments on the product's features and functionality, and your experience using the product. This field is optional.)
0 of 5000 characters

The posting of advertisements, profanity, or personal attacks are prohibited.
Click here to review our site terms of use.

Submit
See more CNET content tagged:
Microsoft SQL Server,
Microsoft SQL Server 2000,
denial of service,
instance,
packet

Get free trials and software from our premier partners

advertisement