CVE-2008-1736

Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result; and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.
Configurations

Configuration 1 (hide)

cpe:2.3:a:comodo:comodo_personal_firewall:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:45

Type Values Removed Values Added
References () http://secunia.com/advisories/30006 - Vendor Advisory () http://secunia.com/advisories/30006 - Vendor Advisory
References () http://securityreason.com/securityalert/3838 - () http://securityreason.com/securityalert/3838 -
References () http://securitytracker.com/id?1019944 - () http://securitytracker.com/id?1019944 -
References () http://www.coresecurity.com/?action=item&id=2249 - () http://www.coresecurity.com/?action=item&id=2249 -
References () http://www.personalfirewall.comodo.com/release_notes.html - () http://www.personalfirewall.comodo.com/release_notes.html -
References () http://www.securityfocus.com/archive/1/491405/100/0/threaded - () http://www.securityfocus.com/archive/1/491405/100/0/threaded -
References () http://www.securityfocus.com/bid/28742 - Patch () http://www.securityfocus.com/bid/28742 - Patch
References () http://www.vupen.com/english/advisories/2008/1383 - () http://www.vupen.com/english/advisories/2008/1383 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42082 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42082 -

Information

Published : 2008-04-30 00:10

Updated : 2024-11-21 00:45


NVD link : CVE-2008-1736

Mitre link : CVE-2008-1736

CVE.ORG link : CVE-2008-1736


JSON object : View

Products Affected

comodo

  • comodo_personal_firewall