The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.
2007-02-07T11:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | broadcom | brightstor_arcserve_backup | 11 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.1 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |