CVE Vulnerabilities

CVE-2002-0643

Published: Jul 23, 2002 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka SQL Server Installation Process May Leave Passwords on System.

Affected Software

Name Vendor Start Version End Version
Data_engine Microsoft 1.0 (including) 1.0 (including)
Sql_server Microsoft 7.0 (including) 7.0 (including)
Sql_server Microsoft 7.0-sp1 (including) 7.0-sp1 (including)
Sql_server Microsoft 7.0-sp2 (including) 7.0-sp2 (including)
Sql_server Microsoft 7.0-sp3 (including) 7.0-sp3 (including)
Sql_server Microsoft 2000 (including) 2000 (including)
Sql_server Microsoft 2000-sp1 (including) 2000-sp1 (including)
Sql_server Microsoft 2000-sp2 (including) 2000-sp2 (including)

References