First published: Sat Apr 27 2002(Updated: )
Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =7.0-sp1 | |
Microsoft SQL Server | =2000-sp2 | |
Microsoft SQL Server | =7.0 | |
Microsoft SQL Server | =2000 | |
Microsoft SQL Server | =2000-sp1 | |
Microsoft SQL Server | =7.0-sp3 | |
Microsoft SQL Server | =7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0154 has a high severity rating due to its potential to allow denial of service and arbitrary code execution.
To fix CVE-2002-0154, it is recommended to apply the latest service packs and security updates for Microsoft SQL Server.
CVE-2002-0154 affects Microsoft SQL Server versions 7.0 and 2000, including their specific service packs.
CVE-2002-0154 allows remote attackers to execute arbitrary code or cause a denial of service via specially crafted database queries.
The exploitation of CVE-2002-0154 can be straightforward for attackers with knowledge of SQL queries and the vulnerability itself.