The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/522408/30/0/threaded | mailing list |
http://www.exploit-db.com/exploits/18688/ | exploit |
http://www.securitytracker.com/id?1026956 | vdb entry |
http://aluigi.altervista.org/adv/dpa_1-adv.txt | exploit |