SHARE
Facebook X Pinterest WhatsApp

Microsoft Patches Vulnerable SQL Servers

Written By
thumbnail
Ryan Naraine
Ryan Naraine
Apr 19, 2002

Microsoft has issued a security patch to two versions of its SQL
Server software that were vulnerable to attackers.

Microsoft said the patch was for a buffer overrun
vulnerability which affected its SQL Server 7.0 and 2000 database software.
In an advisory, the company said the flaw could cause SQL failure or allow
hackers to execute code in the security context in which SQL Server is
running.

“SQL Server can be configured to run in various security contexts, and by
default runs as a domain user. The precise privileges the attacker could
gain would depend on the specific security context that the service runs
in,” Microsoft said.

“An attacker could exploit this vulnerability in one of two ways. Firstly,
the attacker could attempt to load and execute a database query that calls
one of the affected functions. Secondly, if a web-site or other database
front-end were configured to access and process arbitrary queries, it could
be possible for the attacker to provide inputs that would cause the query to
call one of the functions in question with the appropriate malformed
parameters.”

SQL Server 7.0 and 2000 both provide for extended stored procedures, which
are external routines written in a programming language such as C. Microsoft
said these procedures appear to users as normal stored procedures and are
executed in the same way.

The patch for SQL 7.0 is available here and, for SQL Server 2000, it can be found here.

To ensure proper patch installation in 7.0, Microsoft has urged Webmasters
to verify the individual files by consulting the date/time stamp of the
files listed in the file manifest in the Microsoft Knowledge Base article.

For SQL Server 2000, verification of the individual files can be done by
consulting the date/time stamp of the files listed in the file manifest here

Recommended for you...

Oracle’s NetBeans Headed to The Apache Software Foundation
Praise Be to the Dockercon 16 Demo Gods : Drink Espresso #dockercon
Facebook Gets Serious about Open-Source
Python 2 Gets New Security Features, Four Years After It was Supposed to Go Away
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.