CVE-2007-4216

vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:zonealarm:5.0.63.0:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:zonealarm:6.1.744.001:*:*:*:*:*:*:*

History

21 Nov 2024, 00:35

Type Values Removed Values Added
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=585 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=585 -
References () http://secunia.com/advisories/26513 - () http://secunia.com/advisories/26513 -
References () http://securitytracker.com/id?1018589 - () http://securitytracker.com/id?1018589 -
References () http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=53 - () http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=53 -
References () http://www.securityfocus.com/archive/1/477155/100/0/threaded - () http://www.securityfocus.com/archive/1/477155/100/0/threaded -
References () http://www.securityfocus.com/bid/25365 - () http://www.securityfocus.com/bid/25365 -
References () http://www.securityfocus.com/bid/25377 - () http://www.securityfocus.com/bid/25377 -
References () http://www.vupen.com/english/advisories/2007/2929 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2929 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/36107 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/36107 -

Information

Published : 2007-08-21 17:17

Updated : 2024-11-21 00:35


NVD link : CVE-2007-4216

Mitre link : CVE-2007-4216

CVE.ORG link : CVE-2007-4216


JSON object : View

Products Affected

checkpoint

  • zonealarm
CWE
CWE-20

Improper Input Validation