PT-2005-1801 · Veritas · Veritas Backup Exec

Published

2005-06-26

·

Updated

2023-12-28

·

CVE-2005-0772

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions VERITAS Backup Exec versions 9.0 through 10.0 for Windows Servers VERITAS Backup Exec versions 9.0.4019 through 9.1.307 for Netware
Description The issue allows remote attackers to cause a denial of service, resulting in a Remote Agent crash. This can be achieved via a crafted packet in NDMLSRVR.DLL or a request packet with an invalid Error Status value, which triggers a null dereference.
Recommendations For VERITAS Backup Exec versions 9.0 through 10.0 for Windows Servers, consider disabling the NDMLSRVR.DLL until a patch is available to prevent exploitation. For VERITAS Backup Exec versions 9.0.4019 through 9.1.307 for Netware, restrict the use of request packets with invalid Error Status values to minimize the risk of a Remote Agent crash. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2005-0772

Affected Products

Veritas Backup Exec