CVE Database
/

CVE-2002-1137

Back to search

CVE-2002-1137

Published: Sep 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.

VendorProductVersions

n/a

n/a

affected
n/a

References

MS02-056
vendor-advisory
x_refsource_MS
N-003
third-party-advisory
government-resource
x_refsource_CIAC
mssql-dbcc-bo-variant(10255)
vdb-entry
x_refsource_XF
5877
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now