Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: Apps :: web5460.htm

Microsoft SQL Server pwdencrypt() buffer overflow



17th Jun 2002 [SBWID-5460]
COMMAND

	Microsoft SQL Server pwdencrypt() buffer overflow

SYSTEMS AFFECTED

	SQL Server 2000 (up to SP2)

PROBLEM

	Martin Rakhmanoff (jimmers) [jimmers@yandex.ru] found :
	

	Microsoft SQL Server 2000 (up to SP2) suffers from buffer/heap  overflow
	in built-in hashing  function  pwdencrypt().  Sample  code  shown  below
	crashes SQL Server service and may lead to arbitrary code execution:
	

	SELECT pwdencrypt(REPLICATE(\'A\',353))

	

	On some systems it may require  lager  amount  of  characters  to  cause
	overflow (1000 is enough in any case)
	

	

SOLUTION

	None yet.


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH