Microsoft Knowledge Base Email Alertz

MS08-040: Description of the security update for SQL Server 2000 QFE and MSDE 2000: July 8, 2008

Search KbAlertz

Advanced Search

Receive Microsoft Knowledge Base articles by E-Mail?

Every night we scan the Microsoft Knowledge Base. If technologies you're interested in are updated, we'll send you an e-mail. You only get one e-mail a day, and only when new articles are added.

Click here to create a
FREE account
Already have an account?
[Click here to Login]











Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks

Article ID: 948111 - Last Review: April 20, 2009 - Revision: 4.0

MS08-040: Description of the security update for SQL Server 2000 QFE and MSDE 2000: July 8, 2008

System TipThis article applies to a different version of Windows than the one you are using. Content in this article may not be relevant to you. Visit the Windows Vista Solution Center

On This Page

INTRODUCTION

Microsoft has released security bulletin MS08-040. To view the complete security bulletin, visit one of the following Microsoft Web sites:

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.

Known issues with this security update

Microsoft Internet Security and Acceleration (ISA) Server 2004 and ISA Server 2006 could be affected by this update in the following ways:
  • The MSSQL$MSFW service is stopped and then restarted when the associated database instances are updated. This action occurs if Microsoft SQL Server 2000 or Microsoft SQL Server 2000 Desktop Engine (MSDE 2000) is installed on the computer that is running ISA Server. This action also stops the Microsoft Firewall service. Therefore, the SQL Server installer tries to return the Microsoft Firewall service to the same state that it was in before the update was started. Because the update installer cannot control services on a remote server, you must monitor and possibly restart the Microsoft Firewall service and the dependent services if ISA Server is configured for remote SQL Server logging.

    By default, ISA Server disables remote network connectivity for the ISA Server MSDE instance (MSSQL$MSFW) to prevent vulnerability to network-based SQL attacks. ISA Server 2004 Setup installs a pre-SQL Server 2000 Service Pack 4 (SP4) version of MSDE 2000 that you must upgrade to SQL Server 2000 SP4 before you apply this update. For more information about how to obtain SQL Server 2000 SP4, visit the following Microsoft Web site:
    http://www.microsoft.com/downloads/details.aspx?FamilyID=8e2dfc8d-c20e-4446-99a9-b7f0213f8bc5 (http://www.microsoft.com/downloads/details.aspx?FamilyID=8e2dfc8d-c20e-4446-99a9-b7f0213f8bc5)
    The MSDE 2000 component of SQL Server 2000 SP4 is named the SQL2000.MSDE-KB884525-SP4-x86-Lang.exe file. Type the following command at a command prompt to upgrade the instance of ISA Server 2004 MSDE to MSDE 2000 together with SQL Server 2000 SP4:
    setup /upgradesp sqlrun instancename=MSFW /l*v c:\msde2Ksp4.log
    Important The SQL Server 2000 SP4 installer also stops and then tries to restart the Microsoft Firewall service. However, the service may not correctly restart after you install the security update. In this case, you may have to restart the service manually.
  • ISA Server 2006 installs MSDE 2000 together with SQL Server 2000 SP4.

    By default, ISA Server 2000 is not affected by the SQL Server security update. ISA Server 2000 may be configured to use a remote instance of SQL Server for logging. If that instance of SQL Server is updated, ISA Server 2000 may be affected in the same manner as ISA Server 2004 and ISA Server 2006. Because the update installer cannot control services on a remote server, you must monitor and possibly restart the ISA Server services.
  • You cannot install this update by using the SA account.

    You can work around this issue by using the following command to install this update:
    SQL2000-KB948111-v8.00.2273-x86x64-ENU.exe /INSTANCENAME=Name /SAPWD=PASSWORD

File information

The English (United States) version of this security update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

For all supported 32-bit editions of SQL Server 2000 SP4

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatform
Updatelauncher.exe5.2.3790.12888,70420-May-200806:30x86
Spupdsvc.exe6.2.29.025,82428-Nov-200723:10x64
Dtsui.dll2000.80.2273.01,593,34420-May-200806:29x86
Impprov.dll2000.80.2273.0102,40020-May-200806:29x86
Msgprox.dll2000.80.2273.094,20820-May-200806:29x86
Msrpjt40.dll4.10.9424.0188,47320-May-200806:29x86
Mssdi98.dll8.11.50523.0239,10420-May-200806:29x86
Ntwdblib.dll2000.80.2273.0290,81620-May-200806:29x86
Odsole70.dll2000.80.2273.069,63220-May-200806:29x86
Osql.exe2000.80.2273.057,34420-May-200806:29x86
Pfclnt80.dll2000.80.2273.0430,08020-May-200806:29x86
Qrdrsvc.exe2000.80.2273.0192,51220-May-200806:29x86
Replmerg.exe2000.80.2273.0163,84020-May-200806:29x86
Replprov.dll2000.80.2273.0237,56820-May-200806:29x86
Replrec.dll2000.80.2273.0315,39220-May-200806:29x86
Replsub.dll2000.80.2273.0270,33620-May-200806:29x86
Rinitcom.dll2000.80.2273.0278,52820-May-200806:29x86
Semexec.dll2000.80.2273.0856,06420-May-200806:29x86
Semmap.dll2000.80.2273.053,24820-May-200806:29x86
Snapshot.exe2000.80.2273.061,44020-May-200806:29x86
Sqlagent.exe2000.80.2273.0323,58420-May-200806:29x86
Sqldiag.exe2000.80.2273.0118,78420-May-200806:29x86
Sqldmo.dll2000.80.2273.04,362,24020-May-200806:29x86
Sqlfth75.dll2000.80.2273.0102,40020-May-200806:29x86
Sqlservr.exe2000.80.2273.09,183,23220-May-200806:29x86
Sqlsort.dll2000.80.2273.0589,82420-May-200806:29x86
Sqlvdi.dll2000.85.2101.0122,36820-May-200806:29x86
Stardds.dll2000.80.2273.0176,12820-May-200806:29x86
Svrnetcn.dll2000.80.2273.0110,59220-May-200806:29x86
Ums.dll2000.80.2273.035,84020-May-200806:29x86
Xpstar.dll2000.80.2273.0311,29620-May-200806:29x86
Osql.exe2000.80.2039.057,34420-May-200806:30x86
Sqlbootldr.exe1.4.1535.032,76820-May-200806:30x86
Sqlstpcustomdll.dll1.4.1535.03,336,19219-May-200801:21x64
Spupdsvc.exe6.2.29.022,75228-Nov-200723:10x86
Sqlstpcustomdll.dll1.4.1535.02,316,28820-May-200806:30x86

For all supported Itanium-based editions of SQL Server 2000 SP4

Collapse this tableExpand this table
File NameFile VersionFile sizeDateTimePlatform
impprov.dll2000.80.2273.02452483/8/20089:57ia64
MSGPROX.dll2000.80.2273.01889283/8/20089:57ia64
ODSOLE70.dll2000.80.2273.01505283/8/20089:57ia64
OSQL.EXE2000.80.2273.01495043/8/20089:57ia64
PFCLNT80.dll2000.80.2273.011878403/8/20089:57ia64
qrdrsvc.exe2000.80.2273.03568643/8/20089:57ia64
replmerg.exe2000.80.2273.03752963/8/20089:57ia64
REPLPROV.dll2000.80.2273.05391363/8/20089:57ia64
replrec.dll2000.80.2273.07782403/8/20089:57ia64
REPLSUB.dll2000.80.2273.06415363/8/20089:57ia64
rinitcom.dll2000.80.2273.06563843/8/20089:57ia64
semmap.DLL2000.80.2273.01623043/8/20089:57ia64
snapshot.exe2000.80.2273.0911363/8/20089:57ia64
sqlagent.EXE2000.80.2273.010618883/8/20089:54ia64
sqldiag.exe2000.80.2273.03343363/8/20089:57ia64
SQLDMO.dll2000.80.2273.0138603523/8/20089:57ia64
sqlservr.exe2000.80.2273.0250030083/8/20089:57ia64
sqlvdi.dll2000.85.2101.03389443/8/20089:58ia64
SVRNETCN.dll2000.80.2273.04275203/8/20089:58ia64
xpstar.DLL2000.80.2273.08734723/8/20089:58ia64

APPLIES TO
  • Microsoft SQL Server 2000 Service Pack 4
  • Microsoft Windows 2000 Service Pack 4, when used with:
    • Microsoft Windows 2000 Advanced Server
    • Microsoft Windows 2000 Datacenter Server
    • Microsoft Windows 2000 Professional Edition
    • Microsoft Windows 2000 Server
Keywords: 
atdownload kbbug kbexpertiseinter kbfix kbpubtypekc kbsecbulletin kbsecurity kbsecvulnerability KB948111
       

Community Feedback System

Very often, it takes hours to solve a problem. Very often, you've looked high and low, and have tried a lot of solutions. When you finally found it, chances are, it was because someone else helped you. Here's your chance to give back. Use our community feedback tool to let others know what worked for you and what didn't.

Please also understand that the community feedback system is not warranted to be correct, it's simply a system that we've built to let people try and help each other. If something in a feedback response doesn't make sense to you, or you're not comfortable making changes that the feedback talks about (like registry edits), please consult a professional.

Thank you for using kbAlertz.com Feedback System.

-- Scott Cate