Get a Pentest and security assessment of your IT network.

Advisories

Atstake Security Advisory 03-07-08.1

Atstake Security Advisory A070803-1 – By specifying the name of a named pipe instead of a file, as an argument to Microsoft SQL Server’s xp_fileexist extended stored procedure, one can impersonate the user account Microsoft SQL Server is running under. This is due to the behavior of the CreateFile system call and Windows named pipe impersonation. This is not limited to Microsoft SQL Server, but a system wide problem.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31337/a070803-1.txt

Source: https://packetstormsecurity.com/files/31337/Atstake-Security-Advisory-03-07-08.1.html

Related posts
Advisories

Secunia Security Advisory 15661

Advisories

Secunia Security Advisory 18729

Advisories

Debian Linux Security Advisory 1144-1

Advisories

Mandriva Linux Security Advisory 2007.062