Icon of program: Microsoft Security Bullet…

Microsoft Security Bulletin MS02-038 for Windows

By MicrosoftFree
Download.com has chosen not to provide a direct-download link for this product and offers this page for informational purposes only.

Key Details of Microsoft Security Bulletin MS02-038

  • Unchecked Buffer in SQL Server 2000
  • Last updated on 2/29/2024
  • There have been 3 updates
  • Virus scan status:

    Clean (it's extremely likely that this software program is clean)

Download.com has chosen not to provide a direct-download link for this product and offers this page for informational purposes only.

Developer's Description

Unchecked Buffer in SQL Server 2000
This patch eliminates two newly discovered vulnerabilities affecting SQL Server 2000 and MSDE 2000:
  • A buffer overrun vulnerability that occurs in several Database Consistency Checkers (DBCCs) that ship as part of SQL Server 2000. DBCCs are command console utilities that allow maintenance and other operations to be performed on a SQL Server. While many of these are executable only by sysadmin, some are executable by members of the db_owner and db_ddladmin roles as well. In the most serious case, exploiting this vulnerability would enable an attacker to run code in the context of the SQL Server service, thereby giving the attacker complete control over all databases on the server.
  • A SQL injection vulnerability that occurs in two stored procedures used in database replication. One of these can only be run by users who have been assigned the db_owner role; the other, due to a permissions error, could be run by any user who could log onto the server interactively. Exploiting the vulnerability could enable an attacker to run operating system commands on the server, but is subject to significant mitigating factors as discussed below.

Explore More