vendor:
BrightStor Backup
by:
M. Shirk
N/A
CVSS
MEDIUM
Denial of Service (DoS)
119
CWE
Product Name: BrightStor Backup
Affected Version From: Unknown
Affected Version To: BrightStor ARCserve Backup 11.5.2.0 (SP2)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Computer Associates (CA) Brightstor Backup Remote Procedure Call Server DoS (catirpc.dll)
CATIRPC.dll does not properly handle TADDR2UADDR procedures used in RPC communications with the CA RPC Server (Catirpc.exe). This leads to a condition where a null memory pointer is dereferenced. This appears to be only a DoS, but please prove me otherwise. This was tested on BrightStor ARCserve Backup 11.5.2.0 (SP2).
Mitigation:
Apply the latest patches and updates from the vendor.