|
Microsoft Data Access Components Broadcast Reply Buffer Overflow
|
|
Secunia Advisory:
|
SA10616
|
|
|
Release Date:
|
2004-01-13
|
|
Popularity:
|
15,222 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
System access
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
|
| Software: | Microsoft Data Access Components (MDAC) 2.x Microsoft SQL Server 2000
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2003-0903
|
|
Description: Microsoft has reported a vulnerability in MDAC (Microsoft Data Access Components), which potentially can be exploited by malicious people to compromise a vulnerable system.
The problem is that the reply, which MDAC receives when it broadcasts a request to identify all systems running SQL Server, isn't properly verified.
This allows malicious people on the network to send a specially crafted reply, which can cause a buffer overflow and possibly lead to execution of arbitrary code on a system running MDAC or SQL Server.
The vulnerability affects MDAC 2.5, 2.6, 2.7, and 2.8.
MDAC is included in Windows XP, Windows 2000, and Windows 2003 Server.
Third party applications may also install MDAC.
Solution: Microsoft has issued patches.
MDAC 2.5, 2.6, 2.7, and 2.8:
http://www.microsoft.com/downloads/de...-BFCC-87988E062D91&displaylang=en
MDAC 2.8 on Windows 2003 Server 64-Bit systems:
http://www.microsoft.com/downloads/de...-B8C5-643824857EC0&displaylang=en
Original Advisory: Buffer Overrun in MDAC Function Could Allow Code Execution
http://www.microsoft.com/technet/security/bulletin/MS04-003.asp
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|