Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability

Solution:
Prior to installing the fixes, administrators are advised to ensure that all SQL Server processes are inactive. Ensure that all installations of SQL server are patched and reboot the system before restarting the SQL server.

Veritas Software Backup Exec 9.0 ships with some MSDE components and may therefore be prone to this vulnerability. Users are advised to apply the Microsoft fixes to address this vulnerability for Backup Exec.

Microsoft has released SQL Server 2000 SP3a, which contains all of the fixes from SP3. This service pack also allows users to disable netlibs so that SQL Server 2000 will not listen on port 1434. SP3a is directed at users who have not already installed SP3 or wish to disable the netlibs. Please see the SQL Server Homepage for further details.

A specific fix has been released for the Microsoft .NET Framework SDK. See the References section for a link to Microsoft Knowledge Base article 813850 for instructions and download information.

Fixes available:


Microsoft SQL Server 2000

Microsoft Data Engine 2000

Microsoft SQL Server 2000 SP1

Microsoft SQL Server 2000 Desktop Engine

Microsoft SQL Server 2000 SP2







 

Privacy Statement
Copyright 2008, SecurityFocus