OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Microsoft (0_37888_0F0B756C-5457-6C40-B1BF-B4CDDD1694B1_US_at_Newsletters.Microsoft.com)
Date: Thu Oct 03 2002 - 00:04:02 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----

    - ----------------------------------------------------------------------
    Title: Cumulative Patch for SQL Server (Q316333)
    Date: 02 October 2002
    Software: Microsoft SQL Server 7.0
                    Microsoft Data Engine (MSDE) 1.0
                    Microsoft SQL Server 2000
                    Microsoft Desktop Engine (MSDE) 2000
    Impact: Four vulnerabilities, the most serious of which could
                    enable an attacker to gain control over an affected
                    server.
    Max Risk: Critical
    Bulletin: MS02-056

    Microsoft encourages customers to review the Security Bulletin at:
    http://www.microsoft.com/technet/security/bulletin/MS02-056.asp.
    - ----------------------------------------------------------------------

    Issue:
    ======
    This is a cumulative patch that includes the functionality of all
    previously released patches for SQL Server 7.0, SQL Server 2000, and

    Microsoft Data Engine (MSDE) 1.0, Microsoft Desktop Engine (MSDE)
    2000. In addition, it eliminates four newly discovered vulner-
    abilities.
    * A buffer overrun in a section of code in SQL Server 2000
            (and MSDE 2000) associated with user authentication. By
            sending a specially malformed login request to an affected
            server, an attacker could either cause the server to fail or
            gain the ability to overwrite memory on the server, thereby
            potentially running code on the server in the security context
            of the SQL Server service. It would not be necessary for the
            user to successfully authenticate to the server or to be able
            to issue direct commands to it in order to exploit the
            vulnerability.
    * A buffer overrun vulnerability that occurs in one of the
            Database Console Commands (DBCCs) that ship as part of SQL
            Server 7.0 and 2000. In the most serious case, exploiting
            this vulnerability would enable an attacker to run code in
            the context of the SQL Server service, thereby giving the
            attacker complete control over all databases on the server.
    * A vulnerability associated with scheduled jobs in SQL Server
            7.0 and 2000. SQL Server allows unprivileged users to create
            scheduled jobs that will be executed by the SQL Server Agent.
            By design, the SQL Server Agent should only perform job
            steps that are appropriate for the requesting user's priv-
            ileges. However, when a job step requests that an output file
            be created, the SQL Server Agent does so using its own priv-
            ileges rather than the job owners privileges. This creates a
            situation in which an unprivileged user could submit a job
            that would create a file containing valid operating system
            commands in another user's Startup folder, or simply over-
            write system files in order to disrupt system operation

    The patch also changes the operation of SQL Server, to prevent
    non-administrative users from running ad hoc queries against
    non-SQL OLEDB data sources. Although the current operation does
    not represent a security vulnerability, the new operation makes
    it more difficult to misuse poorly coded data providers that might
    be installed on the server.

    Mitigating Factors:
    ====================
    Unchecked buffer in SQL Server 2000 authentication function:
    * This vulnerability on affects SQL Server 2000 and MSDE 2000.
            Neither SQL Server 7.0 nor MSDE 1.0 are affected.
    * If the SQL Server port (port 1433) were blocked at the firewall,
            the vulnerability could not be exploited from the Internet.
    * Exploiting this vulnerability would allow the attacker to
            escalate privileges to the level of the SQL Server service
            account. By default, the service runs with the privileges of a
            domain user, rather than with system privileges.
    Unchecked buffer in Database Console Commands:
    * Exploiting this vulnerability would allow the attacker to
            escalate privileges to the level of the SQL Server service
            account. By default, the service runs with the privileges of a
            domain user, rather than with system privileges.
    * The vulnerability could only be exploited by an attacker who
            could authenticate to an affected SQL Server or has permissions
            to execute queries directly to the server
    * The vulnerability could only be exploited by an attacker who
            could authenticate to an affected SQL Server.
    Flaw in output file handling for scheduled jobs:
    * The vulnerability could only be exploited by an attacker who
            could authenticate to an affected SQL server.

    Risk Rating:
    ============
     - Internet systems: Critical
     - Intranet systems: Critical
     - Client systems: None

    Patch Availability:
    ===================
     - A patch is available to fix this vulnerability. Please read the
       Security Bulletin at
       http://www.microsoft.com/technet/security/bulletin/ms02-056.asp
       for information on obtaining this patch.

    Acknowledgment:
    ===================
    * Issue regarding ad hoc queries against non-SQL OLEDB data
            sources:
            skscan-associates.net and pokleyzzscan-associates.net
    * Unchecked buffer in Database Console Commands:
            Martin Rakhmanoff (jimmersyandex.ru)

    - ---------------------------------------------------------------------

    THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
    PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS
    ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE
    WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
    IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE
    FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
    CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
    MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
    POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
    OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES
    SO THE FOREGOING LIMITATION MAY NOT APPLY.

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 7.1

    iQEVAwUBPZtnnI0ZSRQxA/UrAQGxEgf/SQqcWOkweSv3JcrA8hW1clpy4GE6u9/Q
    wS5o7oPW2gI6K1Ai62Rz/k00AgeVrwZW4tiIMoU7wCyJattef0VNABM4D3b2Bksg
    uOYjdjvfohAsKr3kKP6tmKWcLqtYAkfueYDZqhIFnWhl8nu1IKnY9Ab0+SyRl3um
    q8P7I7wPPZvzcM6MTrh1nOfJhk1M5ELJhKTHkfo60Flc/iPqccZiBwmM1btgzs8x
    udcOWIMc6P1AgqaCSL2Z0cFD+fbyaFLZS7vW1vo1iwe+6F5EnffKUajV5rDh2JaL
    ncKy18yRbo1vgMO7Jnxmr/eVEaaapH7k7WVDELDTKZbArig+O9aukg==
    =XzIw
    -----END PGP SIGNATURE-----


    *******************************************************************

    You have received this e-mail bulletin because of your subscription to the Microsoft Product Security Notification Service. For more information on this service, please visit http://www.microsoft.com/technet/security/notify.asp.
     
    To verify the digital signature on this bulletin, please download our PGP key at http://www.microsoft.com/technet/security/notify.asp.
     
    To unsubscribe from the Microsoft Security Notification Service, please visit the Microsoft Profile Center at http://register.microsoft.com/regsys/pic.asp
     
    If you do not wish to use Microsoft Passport, you can unsubscribe from the Microsoft Security Notification Service via email as described below:
    Send an email to unsubscribe to the Service by following these steps:
    a. Send an e-mail to securremmicrosoft.com. The subject line and the message body are not used to process the subscription request, and can be anything you like.
    b. Send the e-mail.
    c. You will receive a response, asking you to verify that you really want to cancel your subscription. Compose a reply, and put "OK" in the message body. (Without the quotes). Send the reply.
    d. You will receive an e-mail telling you that your name has been removed from the subscriber list.
     
    For security-related information about Microsoft products, please visit the Microsoft Security Advisor web site at http://www.microsoft.com/security.