CVE-2002-0650: Medium severity Microsoft SQL Server vulnerability
The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0650?
CVE-2002-0650 is classified as a denial of service vulnerability.
How do I fix CVE-2002-0650?
To fix CVE-2002-0650, ensure you apply the latest service pack and updates for Microsoft SQL Server 2000.
What systems are affected by CVE-2002-0650?
CVE-2002-0650 affects Microsoft SQL Server 2000 and its service packs, specifically SP1 and SP2.
What attack vector is used in CVE-2002-0650?
CVE-2002-0650 is exploited using spoofed IP addresses to send ping-style packets to the Resolution Service on UDP port 1434.
What impact does CVE-2002-0650 have on systems?
CVE-2002-0650 can lead to bandwidth consumption, causing a denial of service condition for the affected Microsoft SQL Server instances.