|
RPC Invalid Arguments DoS
July 27,2001
There has been a recent Denial of Service discovery in the RPC services that
Microsoft SQL Server uses. We have not seen any attacks in the wild as of
yet, but this hole could be used to bring down your database.
You are not vulnerable to the attack if you have Microsoft SQL Server 7 SP3
or Microsoft SQL Server 2000 SP1. You can also download and install a patch
for systems not yet upgraded to these service packs at:
http://download.microsoft.com/download/sql70/Hotfix/Q298012/WIN98MeXP/EN-US/Q298012_SQL70SP2_x86_en.exe
http://download.microsoft.com/download/SQLSVR2000/Hotfix/Q298012/WIN98MeXP/EN-US/Q298012_SQL2000_x86_en.exe
|