CVE-2005-0772: Null Pointer Dereference
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status" value, which triggers a null dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0772?
CVE-2005-0772 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2005-0772?
To mitigate CVE-2005-0772, update to a patched version of VERITAS Backup Exec beyond 10.0 and 9.1.307.
What systems are affected by CVE-2005-0772?
CVE-2005-0772 affects VERITAS Backup Exec versions 9.0 through 10.0 for Windows Servers and certain versions for Netware.
What type of attack is CVE-2005-0772 associated with?
CVE-2005-0772 is associated with remote denial of service attacks through crafted packets.
Is CVE-2005-0772 exploitable from a remote location?
Yes, CVE-2005-0772 can be exploited by remote attackers, allowing them to crash the Remote Agent.