Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Buffer Overrun in MDAC Could Lead to Code Execution
Posted by philipp on: 11/20/2002 08:52 PM [ Print | 0 comment(s) ]
Microsoft has release a security update for the Microsoft Data Access Components
Software: Microsoft Data Access Components (MDAC) 2.1, Microsoft Data Access Components (MDAC) 2.5, Microsoft Data Access Components (MDAC) 2.6, Microsoft Internet Explorer 5.01, Microsoft Internet Explorer 5.5, and Microsoft Internet Explorer 6.0
Impact: Run code of attacker's choice
Max Risk: Critical
Bulletin: MS02-065
The vulnerability results because of an unchecked buffer in the Data Stub. By sending a specially malformed HTTP request to the Data Stub, an attacker could cause data of his or her choice to overrun onto the heap. Although heap overruns are typically more difficult to exploit than the more-common stack overrun, Microsoft has confirmed that in this case it would be possible to exploit the vulnerability to run code of the attacker's choice on the user's system.
Impact: Run code of attacker's choice
Max Risk: Critical
Bulletin: MS02-065
The vulnerability results because of an unchecked buffer in the Data Stub. By sending a specially malformed HTTP request to the Data Stub, an attacker could cause data of his or her choice to overrun onto the heap. Although heap overruns are typically more difficult to exploit than the more-common stack overrun, Microsoft has confirmed that in this case it would be possible to exploit the vulnerability to run code of the attacker's choice on the user's system.
Read more
Related Threads
04/17/2003 11:24 AM: Buffer Overrun in Windows Kernel Message (0) by KhaineBOT

