CVE-2000-1083: Low severity Microsoft SQL Server vulnerability
The xpshowcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srvparaminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1083?
CVE-2000-1083 is classified as a denial of service vulnerability that could affect the availability of SQL Server and Microsoft Data Engine.
How do I fix CVE-2000-1083?
To fix CVE-2000-1083, update your SQL Server or Microsoft Data Engine to the latest version or apply relevant patches provided by Microsoft.
Which versions are affected by CVE-2000-1083?
CVE-2000-1083 affects Microsoft SQL Server 7.0, Microsoft SQL Server 2000, and Microsoft Data Engine 1.0 and 2000.
What type of attack does CVE-2000-1083 allow?
CVE-2000-1083 allows an attacker to exploit a buffer overflow vulnerability, potentially causing a denial of service.
Is CVE-2000-1083 a critical vulnerability?
While CVE-2000-1083 is a significant vulnerability, it is primarily classified as a denial of service rather than critical remote code execution.