The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=102760196931518&w=2 - | |
References | () http://marc.info/?l=ntbugtraq&m=102760479902411&w=2 - | |
References | () http://www.iss.net/security_center/static/9662.php - | |
References | () http://www.osvdb.org/878 - | |
References | () http://www.securityfocus.com/bid/5312 - | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039 - |
Information
Published : 2002-08-12 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0650
Mitre link : CVE-2002-0650
CVE.ORG link : CVE-2002-0650
JSON object : View
Products Affected
microsoft
- sql_server
CWE