CVE-2002-0056: Buffer Overflow
Published Feb 21, 2002
·Updated
Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.
Affected Software
2 affected components
Microsoft SQL Server=7.0
Microsoft SQL Server=2000
Event History
Feb 21, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0056?
CVE-2002-0056 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2002-0056?
To mitigate CVE-2002-0056, patch your SQL Server installation or upgrade to a newer, supported version.
3
What software is affected by CVE-2002-0056?
CVE-2002-0056 affects Microsoft SQL Server versions 7.0 and 2000.
4
Can CVE-2002-0056 be exploited remotely?
Yes, CVE-2002-0056 can be exploited remotely by attackers sending a specially crafted OLE DB provider name.
5
What are the potential consequences of CVE-2002-0056?
Exploitation of CVE-2002-0056 can allow attackers to execute arbitrary code on the affected SQL Server.