CNCVE编号:CNCVE-20001081 CVE编号:CAN-2000-1081 安全级别:高 漏洞中文描述: SQL Server 和微软SQL Server桌面引擎(MSDE,Microsoft SQL Server Desktop Engine)的xp_displayparamstmt函数不能在调用SQL Server API处理扩展存储过程(XP,Extended Stored Procedures)的srv_paraminfo函数之前正确的限制缓冲区的长度,这将允许攻击者引发拒绝服务和执行任意命令,参看“扩展存储过程参数分析”漏洞。 漏洞英文描述: The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allo 漏洞参考: ATSTAKE:20001201 Microsoft SQL Server extended stored procedure vulnerability | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570878710037&w=2 | MS:MS00-092 | URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp | BID:2030 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误