CVE-2003-0232: Buffer Overflow
Published Jul 25, 2003
·Updated
Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
Affected Software
12 affected components
Microsoft SQL Server=7.0-sp1
Microsoft SQL Server=2000-sp2
Microsoft SQL Server=7.0
Microsoft Data Engine=1.0
Microsoft SQL Server=2000-sp3
Microsoft SQL Server=2000
Microsoft SQL Server=2000-sp1
Microsoft SQL Server=2000-sp3a
Microsoft SQL Server=7.0-sp3
Microsoft SQL Server=2000
Microsoft SQL Server=7.0-sp4
Microsoft SQL Server=7.0-sp2
Remediation
Event History
Jul 25, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0232?
CVE-2003-0232 is classified as critical due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2003-0232?
To fix CVE-2003-0232, install the latest security patches provided by Microsoft for affected SQL Server versions.
3
Which versions of Microsoft SQL Server are affected by CVE-2003-0232?
CVE-2003-0232 affects Microsoft SQL Server versions 7.0, 2000, and Microsoft Data Engine 1.0.
4
Can local users exploit CVE-2003-0232?
Yes, CVE-2003-0232 can be exploited by local users to execute arbitrary code through a crafted request.
5
Is there a workaround for CVE-2003-0232?
While updating to the latest software version is recommended, configuring network settings to limit access may serve as a partial workaround.