CVE-2007-1793

SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:antivirus:10.0:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.1:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.1.1:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2.1:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2.2:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.3:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.4:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.5:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.6:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.7:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.8:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.9:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.0.359:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.1.1000:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.1.1001:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.1.1007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.1.1008:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.1.1009:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2000:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2001:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2002:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2010:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2011:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2020:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0.2.2021:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.0.396:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.0.401:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.400:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1.401:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_360:1.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antispam:2004:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antispam:2005:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2004:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2005:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2008:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2004:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_personal_firewall:2004:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_personal_firewall:2005:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_personal_firewall:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.0.33:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_system_works:2004:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_system_works:2005:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-04-02 22:19

Updated : 2024-02-28 11:01


NVD link : CVE-2007-1793

Mitre link : CVE-2007-1793

CVE.ORG link : CVE-2007-1793


JSON object : View

Products Affected

symantec

  • norton_antivirus
  • norton_internet_security
  • norton_personal_firewall
  • norton_antispam
  • norton_system_works
  • norton_360
  • client_security
  • antivirus
CWE
CWE-20

Improper Input Validation