NT Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 05/31/12
· The Perfect Desktop - Linux Mint 13 (Maya)
· Reliable source says no chance Apple will ax Mac Pro
· Microsoft accidentally announces Windows 8 Release Preview availability to be May 31
· Video Highlights of Tim Cook's D10 Interview
· Install Cinnamon 1.4 on Fedora 17
· Daily Reviews Summary 05/30/12
· Absinthe jailbreaks nearly 1 million iOS devices over holiday weekend
· CompatDB Updates 05/30/12
· Apple CEO Tim Cook slams Windows 8 again

Upcoming News
· Men In Black II (2002) Blu-ray Movie Review
· Dell XPS One 2700 Review @ TechReviewSource.com
· Re: Fedora Board, FESCo, and FAmSCo elections: Town hall meeting schedule
· Cooperative Bug Isolation for Fedora 17
· [CentOS-announce] CEBA-2012:0703 CentOS 6 libatasmart Update
· Intel Ivy Bridge Linux Virtualization Performance
· CyberPower Zeus Thunder 2500 SE Ivy Bridge Gaming System Review @ ThinkComputers.org
· GIGABYTE G1 Sniper M3 Review @ Vortez
· Visiontek GoDrive 60GB and Racer Series 120GB SSD Review
· CM Storm Sentinel Advance II High Performance Laser Gaming Mouse Review

Windows Compatibility
· Realtek High Definition Audio for 2K/XP/03
· Win7codecs x64
· Google Chrome 18.0.1025.168 Final
· IObit Malware Fighter
· Silver
· Advanced SystemCare with Antivirus 2012
· K-Lite Codec Pack Update
· Microsoft Mathematics
· AVZ Antiviral Toolkit
· Intel Turbo Boost Technology Monitor

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Windows XP
· Microsoft
· Updates
· Interviews
· Windows Server 2003
· General
· Windows Vista
· Webcasts
· Windows Server 2008
· Windows Home Server
· Windows 7
· Windows 8
· Windows Phone 7

What's New
Login to see an overview of all news stories since your last visit.

Affiliates

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

NT Compatible » News » April 2002 » SQL Extended Procedure Functions Contain Unchecked Buffers

SQL Extended Procedure Functions Contain Unchecked Buffers

Posted by Philipp Esselbach on: 04/18/2002 12:26 PM [ Print | 0 comment(s) ]

Microsoft has released a new security patch for SQL server




SQL Server 7.0 and 2000 provide for extended stored procedures, which are external routines written in a programming language such as C. These procedures appear to users as normal stored procedures and are executed in the same way. SQL Server 7.0 and 2000 include a number of extended stored procedures which are used for various helper functions

Several of the Microsoft-provided extended stored procedures have a flaw in common - namely, they fail to perform input validation correctly, and are susceptible to buffer overruns as a result exploiting the flaw could enable an attacker to either cause the SQL Server service to fail, or to cause code to run in the security context in which SQL Server is running. SQL Server can be configured to run in various security contexts, and by default runs as a domain user. The precise privileges the attacker could gain would depend on the specific security context that the service runs in.

An attacker could exploit this vulnerability in one of two ways. Firstly, the attacker could attempt to load and execute a database query that calls one of the affected functions. Secondly, if a web-site or other database front-end were configured to access and process arbitrary queries, it could be possible for the attacker to provide inputs that would cause the query to call one of the functions in question with the appropriate malformed parameters.


Read more


Bookmark and Share

« iCute Aluminum Power Supplies Review · Touch Screen LCD Review »

NT Compatible » News » April 2002 » SQL Extended Procedure Functions Contain Unchecked Buffers
All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition