// For flags

CVE-2008-0106

iDEFENSE Security Advisory 2008-07-08.1

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.

Un desbordamiento de búfer en SQL Server 2005 SP1 y SP2, y 2005 Express Edition SP1 y SP2, de Microsoft, permite a usuarios autenticados remotos ejecutar código arbitrario por medio de una sentencia insert diseñada.

Remote exploitation of an integer underflow vulnerability within Microsoft Corp.'s SQL Server could allow a remote attacker to execute arbitrary code with the privileges of the SQL Server. The vulnerability exists within the code responsible for parsing a stored backup file. A 32-bit integer value, representing the size of a record, is taken from the file and used to calculate the number of bytes to read into a heap buffer. This calculation can underflow, which leads to insufficient memory being allocated. The buffer is subsequently overfilled leading to an exploitable condition. iDefense confirmed the existence of this vulnerability in Microsoft SQL Server 2005 Service Pack 2 Hot Fix 4. Additional tests against SQL Server 2005 without any updates suggest it is also vulnerable. Previous versions are also suspected to be vulnerable.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-01-07 CVE Reserved
  • 2008-07-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Data Engine
Search vendor "Microsoft" for product "Data Engine"
1.0
Search vendor "Microsoft" for product "Data Engine" and version "1.0"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2005
Search vendor "Microsoft" for product "Sql Server" and version "2005"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Sql Server Desktop Engine
Search vendor "Microsoft" for product "Sql Server Desktop Engine"
2000
Search vendor "Microsoft" for product "Sql Server Desktop Engine" and version "2000"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server Express Edition
Search vendor "Microsoft" for product "Sql Server Express Edition"
2005
Search vendor "Microsoft" for product "Sql Server Express Edition" and version "2005"
sp2
Affected