CVE-2008-0106
iDEFENSE Security Advisory 2008-07-08.1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
Un desbordamiento de búfer en SQL Server 2005 SP1 y SP2, y 2005 Express Edition SP1 y SP2, de Microsoft, permite a usuarios autenticados remotos ejecutar código arbitrario por medio de una sentencia insert diseñada.
Remote exploitation of an integer underflow vulnerability within Microsoft Corp.'s SQL Server could allow a remote attacker to execute arbitrary code with the privileges of the SQL Server. The vulnerability exists within the code responsible for parsing a stored backup file. A 32-bit integer value, representing the size of a record, is taken from the file and used to calculate the number of bytes to read into a heap buffer. This calculation can underflow, which leads to insufficient memory being allocated. The buffer is subsequently overfilled leading to an exploitable condition. iDefense confirmed the existence of this vulnerability in Microsoft SQL Server 2005 Service Pack 2 Hot Fix 4. Additional tests against SQL Server 2005 without any updates suggest it is also vulnerable. Previous versions are also suspected to be vulnerable.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-01-07 CVE Reserved
- 2008-07-08 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/30970 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/494082/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/516397/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1020441 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA08-190A.html | Third Party Advisory | |
http://www.vmware.com/security/advisories/VMSA-2011-0003.html | X_refsource_confirm | |
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2008/2022/references | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13785 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Data Engine Search vendor "Microsoft" for product "Data Engine" | 1.0 Search vendor "Microsoft" for product "Data Engine" and version "1.0" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2005 Search vendor "Microsoft" for product "Sql Server" and version "2005" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Desktop Engine Search vendor "Microsoft" for product "Sql Server Desktop Engine" | 2000 Search vendor "Microsoft" for product "Sql Server Desktop Engine" and version "2000" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Express Edition Search vendor "Microsoft" for product "Sql Server Express Edition" | 2005 Search vendor "Microsoft" for product "Sql Server Express Edition" and version "2005" | sp2 |
Affected
|