// For flags

CVE-2002-0649

Microsoft SQL Server - Resolution Overflow (MS02-039)

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.

Multiples desbordamientos de buffers en el Servicio de Resolución en SQL Server 2000 y Microsoft Desktop Engine 2000 (MSDE) permite a atacantes remotos causar una denegación de servicio o ejecutar código arbitrario mediante paquetes UDP enviados al puerto 1434 en los que
(1) un byte 0x04 causa al hilo de ejecución del Monitor SQL generar un nombre de clave del registro largo, o (2) un byte 0x08 con una cadena larga causa corrupción en la pila, tal como se realiza en los exploits por el gusano Slammer/Sapphire.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-06-28 CVE Reserved
  • 2002-07-25 First Exploit
  • 2002-07-26 CVE Published
  • 2024-06-25 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (25)
URL Tag Source
http://marc.info/?l=bugtraq&m=102760196931518&w=2 Mailing List
http://marc.info/?l=ntbugtraq&m=102760479902411&w=2 Mailing List
http://www.cert.org/advisories/CA-2002-22.html Third Party Advisory
http://www.cert.org/advisories/CA-2003-04.html Third Party Advisory
http://www.kb.cert.org/vuls/id/399260 Third Party Advisory
http://www.kb.cert.org/vuls/id/484891 Third Party Advisory
http://www.securityfocus.com/archive/1/308306/30/26180/threaded Mailing List
http://www.securityfocus.com/archive/1/308321/30/26180/threaded Mailing List
http://www.securityfocus.com/archive/1/308324/30/26180/threaded Mailing List
http://www.securityfocus.com/archive/1/308388/30/26180/threaded Mailing List
http://www.securityfocus.com/archive/1/308393/30/26180/threaded Mailing List
http://www.securityfocus.com/archive/1/308396/30/26150/threaded Mailing List
http://www.securityfocus.com/archive/1/308418/30/26150/threaded Mailing List
http://www.securityfocus.com/archive/1/308419/30/26150/threaded Mailing List
http://www.securityfocus.com/archive/1/308760/30/26120/threaded Mailing List
http://www.securityfocus.com/archive/1/308806/30/26120/threaded Mailing List
http://www.securityfocus.com/archive/1/309096/30/26120/threaded Mailing List
http://www.securityfocus.com/archive/1/309324/30/26120/threaded Mailing List
http://www.securityfocus.com/archive/1/309776/30/26090/threaded Mailing List
http://www.securityfocus.com/bid/5310 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1077 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Data Engine
Search vendor "Microsoft" for product "Data Engine"
2000
Search vendor "Microsoft" for product "Data Engine" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
sp2
Affected