This application requires Javascript for optimal performance.

MS.SQL.Server.Sp_replwritetovarbin.Memory.Overwrite

Release Date

Jan 08, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a memory corruption vulnerability in Microsoft SQL Server.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted user-supplied parameter to the extended stored procedure "sp_replwritetovarbin". It could allow a remote attacker to execute arbitrary code.

Affected Products

Microsoft SQL Server 2000
Microsoft SQL Server 2005

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-5416

Reference/s

http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovarbin_memwrite.txt
http://secunia.com/advisories/33035/
http://www.securityfocus.com/bid/32710 (BugTraq)
http://www.milw0rm.com/exploits/7501
http://technet.microsoft.com/en-us/security/bulletin/ms09-004.mspx (MS-ID)

Reference: VID-16769