CVE-2008-4844, CVE-2008-5416

December 16th, 2008

The Sourcefire VRT is aware of multiple vulnerabilities affecting Microsoft products.

Details: 

Microsoft Security Advisory (961051):
Microsoft Internet Explorer is vulnerable to an attack that may allow a remote attacker to execute code on an affected system.
 
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15126.
 
Microsoft SQL Server Buffer Overflow (CVE-2008-5416):
A vulnerability in Microsoft SQL Server may allow a remote attacker to execute code on a vulnerable system. This issue may be exploited via the sp_replwritetovarbin stored procedure.
 
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 15127 through 15144.