{ "id": "CVE-2002-0624", "sourceIdentifier": "cve@mitre.org", "published": "2002-07-23T04:00:00.000", "lastModified": "2018-10-12T21:31:33.347", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka \"Unchecked Buffer in Password Encryption Procedure.\"" }, { "lang": "es", "value": "Desbordamiento de b\u00fafer en la funci\u00f3n de encriptaci\u00f3n de contrase\u00f1as en Microsoft SQL Server 2000, incluyendo Microsoft SQL Server Desktop Engine (MSDE) 2000, permite a atacantes remotos la obtenci\u00f3n del control sobre la base de datos y la ejecuci\u00f3n de c\u00f3digo arbitrario mediante SQL Server Authentication .\r\nEsta vulnerabilidad tambi\u00e9n es conocida como Unchecked Buffer in Password Encryption Procedure." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 7.5 }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:msde:2000:*:*:*:*:*:*:*", "matchCriteriaId": "3FF06B44-FC10-49CD-954E-9C4058731A2A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsoft:sql_server:2000:*:*:*:*:*:*:*", "matchCriteriaId": "A5D559EE-727C-405C-987C-247973A84D32" } ] } ] } ], "references": [ { "url": "http://www.cert.org/advisories/CA-2002-22.html", "source": "cve@mitre.org", "tags": [ "US Government Resource" ] }, { "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034", "source": "cve@mitre.org" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A291", "source": "cve@mitre.org" } ] }