Unchecked Buffer in Microsoft SQL Server 2000 and 7.0
There is an unchecked buffer in the handling of OLE database provider names used in ad hoc connections in Microsoft SQL Server 2000 and 7.0. Depending upon the server?s configuration, the unchecked buffer can lead to a buffer overrun condition and remote compromise of the vulnerable server.
You'll find links to Microsoft's own bulletin on this problem and to the patch at the article below.
Unchecked Buffer in Microsoft SQL Server 2000 and 7.0