The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Data_protection_advisor | Emc | 5.5 (including) | 5.5 (including) |
Data_protection_advisor | Emc | 5.5-sp1 (including) | 5.5-sp1 (including) |
Data_protection_advisor | Emc | 5.6 (including) | 5.6 (including) |
Data_protection_advisor | Emc | 5.6-sp1 (including) | 5.6-sp1 (including) |
Data_protection_advisor | Emc | 5.7 (including) | 5.7 (including) |
Data_protection_advisor | Emc | 5.7-sp1 (including) | 5.7-sp1 (including) |
Data_protection_advisor | Emc | 5.8 (including) | 5.8 (including) |
Data_protection_advisor | Emc | 5.8-sp1 (including) | 5.8-sp1 (including) |