Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Community Forums
 Community Discussions (All other subjects)
 Microsoft Security Advisory (961040) - SQL Server
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 23 December 2008 :  15:02:55  Show Profile  Reply with Quote
Microsoft Security Advisory (961040)
Vulnerability in SQL Server Could Allow Remote Code Execution

http://www.microsoft.com/technet/security/advisory/961040.mspx<

SiSL
Average Member

Turkey
671 Posts

Posted - 23 December 2008 :  18:13:05  Show Profile  Visit SiSL's Homepage  Reply with Quote
- This issue does not affect supported editions of Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 Service Pack 3, and Microsoft SQL Server 2008.

- This vulnerability is not exposed anonymously. An attacker would need to either authenticate to exploit the vulnerability or take advantage of a SQL injection vulnerability in a Web application that is able to authenticate.

- By default, MSDE 2000 and SQL Server 2005 Express do not allow remote connections. An authenticated attacker would need to initiate the attack locally to exploit the vulnerability.

Oh well, "Keep your passwords to yourself" advice would be more appropiate in that I guess or move to 2008 asap :p



<

CHIP Online Forum

My Mods
Select All Code | Fix a vulnerability for your private messages | Avatar Categories W/ Avatar Gallery Mod | Complaint Manager
Admin Level Revisited | Merge Forums | No More Nested Quotes Mod
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 24 December 2008 :  04:13:04  Show Profile  Visit MarcelG's Homepage  Reply with Quote
Mmm, just when I migrate to SQL2000 this thing comes out...
Well, let's hope my provider takes the appropriate measures.

Thanks for posting this Richard.<

portfolio - linkshrinker - oxle - twitter
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.1 seconds. Powered By: Snitz Forums 2000 Version 3.4.07