First published: Thu Feb 21 2002(Updated: )
Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =7.0 | |
Microsoft SQL Server | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0056 is considered critical due to its potential for remote code execution.
To mitigate CVE-2002-0056, patch your SQL Server installation or upgrade to a newer, supported version.
CVE-2002-0056 affects Microsoft SQL Server versions 7.0 and 2000.
Yes, CVE-2002-0056 can be exploited remotely by attackers sending a specially crafted OLE DB provider name.
Exploitation of CVE-2002-0056 can allow attackers to execute arbitrary code on the affected SQL Server.