15 pts.
 MS SQL Server 2000 Vulnerability
Hello,

I have installed on one of my servers SQL Server 8.00.2273 - SP4 (Standard Edition). At the last vulnerability tests it founds the followings:

1. Microsoft SQL Server MTF Data Structures Memory Corruption Vulnerability (MS08-040)

2. Microsoft SQL Server 'sp_replwritetovarbin' Remote Memory Corruption Vulnerability (MS09-004)

Searching for an answer at microsoft I found that the latest version of SQL can solve my vulnerabilities. Even if I update the SQL to version 8.00.2282 the vulneranilities are still on.

Can someone please help me to solve these issues?

Thank you very much,

Marius



Software/Hardware used:
Microsoft Windows Server 2003 R2, Standard Edition, SP2
ASKED: October 16, 2009  7:17 AM
UPDATED: October 19, 2009  12:29 PM

Answer Wiki:
You'll want to install this <a href=" http://www.microsoft.com/downloads/details.aspx?familyid=4FD1F86A-94A2-43D8-9B0A-774C81426D9E&displaylang=en">Security update for SQL 2000 Sp4</a> to resolve MS08-040. You'll want to install this <a href="http://www.microsoft.com/downloads/details.aspx?familyid=d5bb816a-6e1a-47cb-92be-51c565ee184c&displaylang=en">Security update for SQL 2000 SP4</a> to resolve MS09-004.
Last Wiki Answer Submitted:  October 16, 2009  8:27 am  by  Denny Cherry   64,550 pts.
All Answer Wiki Contributors:  Denny Cherry   64,550 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 

Hi,

Thank you for the fast reply but didn’t help me.
These updates were already done and unfortunatelly I still have the mentioned vulnerabilties.
Any other idea?

Thanks and regards,

Marius

 15 pts.

 

What tool are you using that is telling you that you still are open to these vulnerabilities?

 64,550 pts.

 

You could be getting a false positive on these…

 11,040 pts.