Vulnerabilities > CVE-2006-0995 - Remote Denial of Service vulnerability in EMC Dantz Retrospect Backup Client

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
emc-dantz
nessus

Summary

EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error. This vulnerability affects EMC Dantz, Retrospect versions 7.0.x (all 7.0.x versions previous to 7.0.109) as well as versions 6.5.x (all 6.5.x versions previous to 6.5.138)

Vulnerable Configurations

Part Description Count
Application
Emc_Dantz
2

Nessus

NASL familyMisc.
NASL idRETROSPECT_CLIENT_DOS.NASL
descriptionAccording to its version number, the installed instance of Retrospect Client for Windows reportedly will stop working if it receives a packet starting with a specially crafted sequence of bytes. An unauthenticated, remote attacker may be able to leverage this flaw to prevent the affected host from being backed up.
last seen2020-06-01
modified2020-06-02
plugin id20996
published2006-03-03
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/20996
titleRetrospect Client Malformed Packet DoS