Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.
| Software | From | Fixed in |
|---|---|---|
| protegrity / secure.data | 2.2.3.8 | 2.2.3.8.x |
| protegrity / secure.data | 2.2.3.7 | 2.2.3.7.x |