|
AppDetective™ Update 2.5.74 - 22 August 2002
NEW CHECKS
Microsoft SQL Server (Pen Test/Security Audit)
Title: DBCC BUFFER buffer overflow
Summary: The built-in function DBCC BUFFER contains a buffer overflow that may allow an attacker to overwrite the stack and execute arbitrary code under the security context of the database. The second parameter of the function does not properly handle a long string.
Title: DBCC PROCBUF buffer overflow
Summary: The built-in function DBCC PROCBUF contains a buffer overflow that may allow an attacker to overwrite the stack and execute arbitrary code under the security context of the database. The second parameter of the function does not properly handle a long string.
Return to ASAP™ Updates Listing
|