First published: Sun Jun 26 2005(Updated: )
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status" value, which triggers a null dereference.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
>=9.0<=10.0 | ||
>=9.0.4019<=9.1.307 | ||
Symantec Veritas Backup Exec | =10.0 | |
Symantec Veritas Backup Exec | =10.0_sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0772 has a medium severity rating due to its potential to cause denial of service.
To mitigate CVE-2005-0772, update to a patched version of VERITAS Backup Exec beyond 10.0 and 9.1.307.
CVE-2005-0772 affects VERITAS Backup Exec versions 9.0 through 10.0 for Windows Servers and certain versions for Netware.
CVE-2005-0772 is associated with remote denial of service attacks through crafted packets.
Yes, CVE-2005-0772 can be exploited by remote attackers, allowing them to crash the Remote Agent.