MS: SQL Server Remote Data Source Function Contain Unchecked Buffers

By Bill Graziano on 20 February 2002 | 0 Comments | Tags: Hot Fixes


From TechNet: An unchecked buffer exists in the handling of OLE DB provider names in ad hoc connections. A buffer overrun could occur as a result and could be used to either cause the SQL Server service to fail, or to cause code to run in the security context of the SQL Server. SQL Server can be configured to run in various security contexts, and by default runs as a domain user. The precise privileges the attacker could gain would depend on the specific security context that the service runs in. Follow the link to MS: SQL Server Remote Data Source Function Contain Unchecked Buffers...

Discuss this article: 0 Comments so far. Print this Article.

If you like this article you can sign up for our weekly newsletter. There's an opt-out link at the bottom of each newsletter so it's easy to unsubscribe at any time.

Email Address:

Related Articles

Microsoft Security Bulletin MS02-061 : Elevation of Privilege in SQL Server Web Tasks (Q316333) (21 October 2002)

New SQL Server Cumulative Security Patch (3 October 2002)

SQL Server 2000 Cumulative Security Update ... Again. (16 August 2002)

Cumulative Patch for SQL Server 2000 (11 July 2002)

New Sql Server Buffer Overrun issue (17 June 2002)

Worm squirming through SQL servers (21 May 2002)

Unchecked Buffer in Extended Stored Procedures (17 April 2002)

SQL Injection White Paper (2 April 2002)

Other Recent Forum Posts

view to be indexed but has a subquery (4 Replies)

Count for 2 fields-Help (9 Replies)

Issue with installing SQL Server Express 2012 (2 Replies)

help with querring dB for first name /last name (3 Replies)

Msg 4104 (43 Replies)

Row_Number() Over Partition By() (0 Replies)

Joining data (8 Replies)

Query help (0 Replies)

Subscribe to SQLTeam.com

Weekly SQL Server newsletter with articles, forum posts, and blog posts via email. Subscribers receive our white paper with performance tips for developers.

SQLTeam.com Articles via RSS

SQLTeam.com Weblog via RSS

- Advertisement -