BindView Corporation Information for VU#484891
Microsoft SQL Server 2000 contains stack buffer overflow in SQL Server Resolution Service
- Vendor Information Help Date Notified: 13 Feb 2003
- Statement Date:
- Date Updated: 20 Feb 2003
Approximately 24 hours after the announcement of the vulnerability exploited by SQL Slammer (aka, Sapphire) in July, 2002, BindView provided it's customers with a tool for identifying vulnerable systems. BindView products have a requirement for customers to use either MSDE or SQL, which are vulnerable if unpatched. Guidance provided to customers at that time recommended immediate installation of the patches to correct the vulnerability. BindView re-issued both the tools and the guidance immediately after the initial outbreak of SQL Slammer.
Technical Note: Where BindView products require MSDE or SQL installed, the patches published by Microsoft will support BindView installations. No additional special patches are required.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.