SQL 7.0 DoS - 16 Dec 1999

 
SQL 7.0 Denial of Server
Reported December 20, 1999 by
Kevork Belian

VERSIONS AFFECTED
Microsoft SQL Server 7.0

DESCRIPTION

Kevork reported a problem with SQL Server 7.0 on November 19, 1999. One month later, Microsoft responds with a patch.

According to the bulletin released by Microsoft, "If a specially-malformed TDS packet is sent to a SQL server, it can cause
the SQL service to crash. This vulnerability would not allow any inappropriate access to the data on the server, nor would it allow a
malicious user to usurp any administrative control on the machine. An
affected machine could be put back into service by restarting the SQL service. This vulnerability could only be remotely exploited if port 1433 were open at the firewall."

Kevork informs us that "SQL Server 7.0 silently crashes when sent a TCP packet containing more than 2 NULLs as data." -- so there you have the structure for "specially-malformed TDS packet."

VENDOR RESPONSE

Microsoft released a FAQ, Support Online article Q249749, and a patch for Intel and Alpha to correct this matter.

CREDITS
Discovered by
Kevork Belian

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish