CVE-2002-0650

Microsoft SQL Server 2000 - Denial of Service via Spoofed Resolution Service Ping

Title source: llm
STIX 2.1

Description

The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=102760479902411&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102760196931518&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5312
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9662.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/878

Scores

EPSS 0.1829
EPSS Percentile 96.9%

Details

Status published
Products (1)
microsoft/sql_server 2000 (3 CPE variants)
Published Aug 12, 2002
Tracked Since Feb 18, 2026