Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0107 (sql_server, data_engine, sql_server_desktop_engine, sql_server_express_edition)

BugsAlert Home > CVE-2008-0107 (sql_server, data_engine, sql_server_desktop_engine, sql_server_express_edition)
 
 

Integer underflow in Microsoft SQL Server 7.0 SP4, 2000 SP4, 2005 SP2, Microsoft Data Engine (MSDE) 1.0 SP4, SQL Server 2000 Desktop Engine (MSDE 2000) SP4, and 2005 Express Edition SP2 allows remote authenticated users to execute arbitrary code via an on-disk file with a crafted record size value, which triggers a buffer overflow, aka "SQL Server Memory Corruption Vulnerability."




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0107

Learn more about CVE-2008-0107 (sql_server, data_engine, sql_server_desktop_engine, sql_server_express_edition)
 
Tags: cve-2008-0107 sql server data engine sql server
 desktop engine sql server express edition

Related Items

      FrSIRT - MailEnable IMAP Connections Denial of Service Vulnerability

      pam_mount "passwdehd" Insecure Temporary Files

      Any idea which bug this is?

      FrSIRT - Gentoo Security Update Fixes WML Insecure Temporary Creation Issues

      Cisco Unified Presence SIP Proxy Service Denial of Service

      FrSIRT - Redhat Security Update Fixes Java Multiple Code Execution Issues

      GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution

 

Pixel