CVE
- Id
- 5034
- CVE No.
- CVE-2002-0644
- Status
- Candidate
- Description
- Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
- Phase
- Proposed (20020726)
- Votes
- ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox
- Comments
- Christey> BUGTRAQ:20020725 SQL Server 2000 Buffer Overflows and SQL Inyection vulnerabilities. | URL:http://online.securityfocus.com/archive/1/284382 | XF:mssql-dbcc-bo(9659) | URL:http://www.iss.net/security_center/static/9659.php | Add details to desc. Affected functions are: | (1)ADDEXTENDEDPROC, (2) INDEXFRAG, (3) UPDATEUSAGE, (4) | CHECKCONSTRAINTS, (5) SHOWCONTIG, and (6) CLEANTABLE. | Frech> XF:mssql-dbcc-bo(9659)