Skip to main content

Microsoft SQL Server Multiple Vulnerabilities( 09 July 2008 )

Last Update Date: 28 Jan 2011 Release Date: 9 Jul 2008 4733 Views

RISK: Medium Risk

1. Memory Page Reuse Vulnerability

An information disclosure vulnerability exists in the way that SQL Server manages memory page reuse. An attacker with database operator access who successfully exploited this vulnerability could access customer data.

2. Convert Buffer Overrun

A vulnerability exists in the convert function in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.

3. SQL Server Memory Corruption Vulnerability

A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.

4. SQL Server Buffer Overrun Vulnerability

A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.


Impact

  • Elevation of Privilege

System / Technologies affected

  • SQL Server 7.0
  • SQL Server 2000
  • Microsoft Data Engine (MSDE) 1.0
  • Microsoft SQL Server 2000 Desktop Engine (MSDE 2000)
  • Microsoft SQL Server 2005 Express Edition
  • Microsoft Windows 2000
    - Microsoft SQL Server 2000 Desktop Engine (WMSDE)
  • Windows Server 2003
    - Microsoft SQL Server 2000 Desktop Engine (WMSDE)
    - Windows Internal Database (WYukon)
  • Windows Server 2008
    - Windows Internal Database (WYukon)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link