Microsoft needs more than half a year to fix vulnerability in SQL Server
17th January 2009
The company Microsoft officially acknowledged that they work, though in vain, to eliminate a vulnerabilities in SQL Server, discovered in April 2008 (!).
Microsoft specialists acknowledged the error in a private correspondence, and a letter from them from 29 September ran that they already made corrections. Nevertheless, there was no official report on releasing a patch to fix the vulnerability. The reaction came immediately: a SEC Consult Security specialist, Muller published on the website of the company a detailed description of the vulnerability and ways to use it.
The vulnerability, discovered by Muller, can be found in such widespread versions of SQL Server as SQL Server 2000, SQL Server 2005, SQL Server 2005 Express Edition, SQL Server 2000 Desktop Engine, Microsoft SQL Server 2000 Desktop Engine and Windows Internal Database. They are being used in millions of apps worldwide.
Meanwhile, Microsoft issued a recommendation to bypass the vulnerability, but not a word of any coming up patch. Apparently, they need another 6 months to fix it up.
Mobile mail service Mail on Ovi from Nokia
K-Meleon 1.5.2: fast and up-to-date Windows browser Featured downloads
Interact
Now downloading
Active Pacman
Active Pacman is a free version of the popular Pacman game featuring top strip models. Active Pacman...
Active Pacman is a free version of the popular Pacman game featuring top strip models. Active Pacman...
Blog categories
News blog











Download Free trial