First published: Tue Jul 08 2008(Updated: )
Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server Data Engine | =2000-sp4 | |
Microsoft SQL Server Express | =2005-sp2 | |
Microsoft SQL Server | =7.0-sp4 | |
Microsoft SQL Server | =2005-sp2 | |
Microsoft SQL Server Data Engine (MSDE) | =1.0-sp4 | |
Microsoft SQL Server | =2000-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0106 is classified as a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary code.
To mitigate CVE-2008-0106, it is recommended to apply the latest security patches provided by Microsoft for affected SQL Server versions.
CVE-2008-0106 affects Microsoft SQL Server 2005 SP1, SP2, and the 2005 Express Edition SP1, SP2.
Yes, CVE-2008-0106 can be exploited by remote authenticated users through crafted insert statements.
CVE-2008-0106 is a buffer overflow vulnerability that can lead to arbitrary code execution.