|
|
Microsoft Data Access Components ODBC远程缓冲区溢出漏洞 发布时间:2003-08-20 更新时间:2003-08-21 严重程度:高 威胁程度:远程管理员权限 错误类型:边界检查错误 利用方式:客户机模式
BUGTRAQ ID:8455 CVE(CAN) ID:CAN-2003-0353
受影响系统Microsoft MDAC 2.5 SP2
Microsoft MDAC 2.5 SP1
Microsoft MDAC 2.5 RTM
Microsoft MDAC 2.5
+ Microsoft Office 2000 SP2
+ Microsoft Office 2000 SR1
+ Microsoft SQL Server 7.0 SP2
+ Microsoft SQL Server 7.0 SP2 alpha
+ Microsoft SQL Server 7.0 SP3
+ Microsoft SQL Server 7.0 SP3 alpha
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server SP2
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000 Datacenter Server SP1
+ Microsoft Windows 2000 Datacenter Server SP2
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional SP2
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server SP2
+ Microsoft Windows 2000 Server Japanese Edition
+ Microsoft Windows 2000 Terminal Services
+ Microsoft Windows 2000 Terminal Services SP1
+ Microsoft Windows 2000 Terminal Services SP2
Microsoft MDAC 2.6 SP2
Microsoft MDAC 2.6 SP1
Microsoft MDAC 2.6 RTM
Microsoft MDAC 2.6
+ Microsoft SQL Server 2000
+ Microsoft SQL Server 2000 SP1
+ Microsoft SQL Server 2000 SP2
+ Microsoft SQL Server 2000 Desktop Engine
Microsoft MDAC 2.7 RTM Refresh
Microsoft MDAC 2.7
+ Microsoft Visual Studio .NET Academic Edition
+ Microsoft Visual Studio .NET Enterprise Architect Edition
+ Microsoft Visual Studio .NET Enterprise Developer Edition
+ Microsoft Visual Studio .NET Professional Edition
+ Microsoft Visual Studio .NET Trial Edition
+ Microsoft Windows XP
+ Microsoft Windows XP 64-bit Edition
+ Microsoft Windows XP Home
+ Microsoft Windows XP Professional 详细描述 Mirosoft Data Access Components (MDAC)是用于提供数据库互连的组件。
Microsoft Data Access Components存在一个缓冲区溢出漏洞允许攻击者在客户端执行任意代码。此问题在当客户端或SQL服务器实现的SQL-DMO库上重现。
SQL网络库可用于对网络上的SQL服务进行查询,如客户端可以提交广播包进行SQL服务器列表查询,如果服务器通过超长的数据包对这个广播进行响应,可导致客户端产生缓冲区溢出,可能导致任意代码执行。
测试代码 尚无
解决方案 补丁下载:
http://microsoft.com/downloads/details.aspx?FamilyId=9107ABC6-8995-4A99-B6A0-478B3A847E9C&displaylang=en
相关信息 参考:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-033.asp
http://www.securityfocus.com/archive/1/334436
|