Patch Management Software
 
MDAC 2.5 Patch DetailsMDAC 2.5 Patches

Patch Name : MDAC252.832483
Patch Description : Security Update for MDAC 252 (832483)
Bulletin Id : MS04-003
Bulletin Title : Buffer Overrun in MDAC Function Could Allow code execution (832483)
KnowledgeBase :832483
Severity : Important
Location Path :MDAC252.832483
Bulletin Summary: Microsoft Data Access Components (MDAC) is a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client. When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. Due to a vulnerability in a specific MDAC component, an attacker could respond to this request with a specially crafted packet that could cause a buffer overflow.

An attacker who successfully exploited this vulnerability could gain the same level of privileges over the system as the application that initiated the broadcast request. The actions an attacker could carry out would be dependent on the permissions under which the application using MDAC ran. If the application ran with limited privileges, an attacker would be limited accordingly; however, if the application ran under the local system context, the attacker would have the same level of permissions.
Superceding Bulletin Id : None
Patch Release Date : Jan 13, 2004
CVE Id :CVE-2003-0903
Affected Product Information  
Product Name Service Pack Name
MDAC 2.5MDAC 2.5 SP2
File changes  
File Path Version
%windir%\system32\odbc32.dll3.520.6101.0
%windir%\system32\odbcbcp.dll3.70.11.46
%windir%\system32\odbccp32.dll3.520.6101.0
%windir%\system32\sqlsrv32.dll3.70.11.46
Registry changes  
Registry Path Key Name Key Value
No records found

 
Disclaimer: This webpage is intended to provide you information about patch announcements for certain specific software products. The information is provided "As Is" without warranty of any kind. The links provided point to pages on the vendors' websites. You can get more information by clicking the links to visit the relevant pages on the vendors' websites. Desktop Central is NOT endorsed by the vendors of the software products.
© 2010, ZOHO Corp. All rights reserved. Trademarks | Privacy Policy | Site Map | Contact Us | Careers | Tell Us