CVE-2002-1137: Buffer Overflow
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1137?
CVE-2002-1137 is considered critical due to its potential for remote code execution.
How do I fix CVE-2002-1137?
To mitigate CVE-2002-1137, apply the latest patches and updates provided by Microsoft for affected SQL Server versions.
What software is impacted by CVE-2002-1137?
CVE-2002-1137 affects Microsoft SQL Server 7.0 and 2000, including specific service pack versions and Microsoft Data Engine.
What type of vulnerability is CVE-2002-1137?
CVE-2002-1137 is a buffer overflow vulnerability that can be exploited via the Database Console Command.
Can CVE-2002-1137 allow for unauthorized access?
Yes, CVE-2002-1137 can potentially allow attackers to execute arbitrary code, leading to unauthorized access.