CVE-2008-0086 Information

Description

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4 2000 Desktop Engine (MSDE 2000) SP4 and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

Reference

http://secunia.com/advisories/30970 http://www.securityfocus.com/archive/1/494082/100/0/threaded http://www.securityfocus.com/archive/1/516397/100/0/threaded http://www.securitytracker.com/id?1020441 http://www.us-cert.gov/cas/techalerts/TA08-190A.html http://www.vmware.com/security/advisories/VMSA-2011-0003.html http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html http://www.vupen.com/english/advisories/2008/2022/references https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A14052

Share on: