Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2008-07-08 23:41
Updated : 2024-02-04 17:33
NVD link : CVE-2008-0107
Mitre link : CVE-2008-0107
CVE.ORG link : CVE-2008-0107
JSON object : View
Products Affected
microsoft
- sql_server_desktop_engine
- windows_2003_server
- wmsde
- data_engine
- windows_server_2008
- sql_server
- wyukon
- windows_server_2003
CWE
CWE-189
Numeric Errors