CVE-2002-0649: Buffer Overflow
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0649?
CVE-2002-0649 has a high severity due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2002-0649?
To fix CVE-2002-0649, apply the latest service pack or update for Microsoft SQL Server and Microsoft Data Engine.
What software versions are affected by CVE-2002-0649?
CVE-2002-0649 affects Microsoft SQL Server 2000 and Microsoft Data Engine 2000, specifically versions up to Service Pack 2.
What type of attack is possible with CVE-2002-0649?
CVE-2002-0649 allows attackers to exploit buffer overflows via specially crafted UDP packets to port 1434.
Is there an exploit available for CVE-2002-0649?
Yes, there are known exploits for CVE-2002-0649 that can cause a denial of service or execute arbitrary code.