ID

VAR-200703-0615


CVE

CVE-2007-1476


TITLE

Symantec Norton Personal Firewall Such as SYMTDI.SYS Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2007-005251

DESCRIPTION

The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855. Symantec 'SYMTDI.SYS' device driver is prone to a local denial-of-service vulnerability. A local authenticated attacker may exploit this issue to crash affected computers, denying service to legitimate users. This issue is similar to the one described in BID 22961. Symantec is currently investigating this issue; we will update this BID as more information emerges. Norton Personal Firewall does not adequately protect its \Device\SymEvent driver and does not validate input buffers, so a local attacker can open the driver and send arbitrary data that is considered valid. A specially crafted IRP sent to an IOCTL handler function could allow memory to be overwritten because the address space was not properly validated in some versions of the driver. A potential attacker must be logged into the computer to attempt an exploit. A successful exploit of this vulnerability could potentially allow that user to crash their computer. Symantec Response Symantec engineers have verified that the vulnerability exists in the products listed in the Affected Products section above, and have provided updates for all affected products. Consumer (Norton) products can be updated by running LiveUpdate. Symantec AntiVirus Corporate Edition customers can obtain the update from the Symantec web site. Symantec is not aware of any customers impacted by this issue, or of any attempts to exploit the issue. References This issue is a candidate for inclusion in the Common Vulnerabilities and Exposures (CVE) list (http://cve.mitre.org), which standardizes names for security problems. The CVE initiative has assigned CVE-2007-1476 to this issue. SecurityFocus has assigned BID 22977 to this vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Symantec Product Security -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.6 (Build 6060) iQEVAwUBRuVg1/9Lqygkbb6BAQiy8gf/aQDO+uftL8+Ia+FLbnOuuEUzfR/LWBHn SFSBw8hk38Gq4DAGMYeBI2Am74cUxjWQ5e3NqG4sQgHD2bfjTkrcPdMabiL8JaM9 j8TaCNBxgyClAcfI79dFinbgBTg4tNMfLbcLeg31gKV64WhQ962cfiZhbURXseS9 gdQMhVEDyyalFvpFFhtWkY+XigLMFeEMeMdjC77nw4jedwgQBS0FV4IAnGn8diHN 2yEHef2I4/pUj8JxHSV2DY5FudWaAc3TbdesBi5jVA/aXg2DOwHGrq05QRG1/qbp /45TREnS+hw0w3xyGs1JbZH0vlqiWoWjwKkv+xrL46bJ7laCTVON3Q== =Cd3j -----END PGP SIGNATURE-----

Trust: 2.07

sources: NVD: CVE-2007-1476 // JVNDB: JVNDB-2007-005251 // BID: 22977 // VULHUB: VHN-24838 // PACKETSTORM: 59201

AFFECTED PRODUCTS

vendor:symantecmodel:client securityscope:eqversion:3.1

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.394

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.400

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.396

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2020

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2011

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2021

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.401

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.0.396

Trust: 1.6

vendor:symantecmodel:client securityscope:eqversion:3.1.0.401

Trust: 1.6

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1008

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.0.359

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1001

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:2.0

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:2.0.4

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:2006

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2000

Trust: 1.3

vendor:symantecmodel:norton personal firewallscope:eqversion:2005

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:2005

Trust: 1.3

vendor:symantecmodel:norton internet securityscope:eqversion:2005

Trust: 1.3

vendor:symantecmodel:norton personal firewallscope:eqversion:2006

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1000

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2010

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2001

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1007

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2002

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.401

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:3.0.2

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.3_build_9.0.3.1000

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.1

Trust: 1.0

vendor:symantecmodel:norton system worksscope:eqversion:2005

Trust: 1.0

vendor:symantecmodel:norton antispamscope:eqversion:2005

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.2

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2002

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.1.1000

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.5

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.1.1.1000

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2000

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.1.1000

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2006_9.1.0.33

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.5.1100

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.5_build_1100

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.3.1000

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.396

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.4

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.6.1000

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0_scf_7.1

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.4

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.4.4010

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0_stm_build_9.0.0.338

Trust: 1.0

vendor:symantecmodel:norton system worksscope:eqversion:2006

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2010

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:lteversion:2006_9.1.1.7

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2011

Trust: 1.0

vendor:symantecmodel:norton internet securityscope:eqversion:2006

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.2.1000

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.2

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.0.338

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1009

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.1_build_9.0.1.1000

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.2_build_9.0.2.1000

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:3.0

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.6

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.1.1008

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.394

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2020

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1.400

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.1

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.1.1007

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.5

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.5_build_1100_mp1

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.1

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2001

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:2.0.3

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:9.0.1

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:10.0.2.2021

Trust: 1.0

vendor:symantecmodel:client securityscope: - version: -

Trust: 0.8

vendor:symantecmodel:norton antispamscope: - version: -

Trust: 0.8

vendor:symantecmodel:norton antivirusscope:eqversion:corporate edition 3.0.x to 10.1.x

Trust: 0.8

vendor:symantecmodel:norton internet securityscope:eqversion:2005 and 2006

Trust: 0.8

vendor:symantecmodel:norton personal firewallscope:lteversion:2006 9.1.1.7

Trust: 0.8

vendor:symantecmodel:norton systemworksscope: - version: -

Trust: 0.8

vendor:symantecmodel:client securityscope:eqversion:3.1.6.6000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2010

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.0.338

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr4 buildscope:eqversion:9.0.41000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.6.1000

Trust: 0.3

vendor:symantecmodel:client security mr6scope:eqversion:2.0.6

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:20060

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1007

Trust: 0.3

vendor:symantecmodel:norton personal firewallscope:eqversion:20069.1.1.7

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr6 mp1scope:neversion:9

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr6 mp1scope:neversion:10.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.394

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.5.1100

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.6.600

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.6.6000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2001

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.400

Trust: 0.3

vendor:symantecmodel:client security mr6scope:eqversion:3.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.401

Trust: 0.3

vendor:symantecmodel:client security mr4 mp1 buildscope:eqversion:3.1.4-4010

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.396

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.4.4010

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.3.1000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0

Trust: 0.3

vendor:symantecmodel:client security stm buildscope:eqversion:2.09.0.0.338

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2020

Trust: 0.3

vendor:symantecmodel:client security mr3 b9.0.3.1000scope:eqversion:2.0.3

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.2.1000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1000

Trust: 0.3

vendor:symantecmodel:client security (scfscope:eqversion:2.07.1)

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.5

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr6scope:eqversion:10.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.4

Trust: 0.3

vendor:symantecmodel:norton personal firewallscope:eqversion:20069.1.33

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1008

Trust: 0.3

vendor:symantecmodel:client security buildscope:eqversion:2.0.51100

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2002

Trust: 0.3

vendor:symantecmodel:client security mr6 mp1scope:neversion:3.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1

Trust: 0.3

vendor:symantecmodel:client security mr2 b9.0.2.1000scope:eqversion:2.0.2

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2011

Trust: 0.3

vendor:symantecmodel:client security mr1 b9.0.1.1000scope:eqversion:2.0.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2021

Trust: 0.3

vendor:symantecmodel:norton antispamscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.1.1.1000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.0.359

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:9.0.4

Trust: 0.3

vendor:symantecmodel:client security mr6 mp1scope:neversion:2.0

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr4 mp1 buildscope:eqversion:10.1.4-4010

Trust: 0.3

vendor:symantecmodel:client security mr4 buildscope:eqversion:2.0.41000

Trust: 0.3

sources: BID: 22977 // JVNDB: JVNDB-2007-005251 // CNNVD: CNNVD-200703-393 // NVD: CVE-2007-1476

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-1476
value: LOW

Trust: 1.0

NVD: CVE-2007-1476
value: LOW

Trust: 0.8

CNNVD: CNNVD-200703-393
value: LOW

Trust: 0.6

VULHUB: VHN-24838
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2007-1476
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-24838
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-24838 // JVNDB: JVNDB-2007-005251 // CNNVD: CNNVD-200703-393 // NVD: CVE-2007-1476

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-24838 // JVNDB: JVNDB-2007-005251 // NVD: CVE-2007-1476

THREAT TYPE

local

Trust: 0.9

sources: BID: 22977 // CNNVD: CNNVD-200703-393

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200703-393

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-005251

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-24838

PATCH

title:SYM07-024url:http://www.symantec.com/avcenter/security/Content/2007.09.05.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-005251

EXTERNAL IDS

db:NVDid:CVE-2007-1476

Trust: 2.9

db:BIDid:22977

Trust: 2.0

db:SREASONid:2438

Trust: 1.7

db:SECTRACKid:1018656

Trust: 1.7

db:OSVDBid:35088

Trust: 1.7

db:JVNDBid:JVNDB-2007-005251

Trust: 0.8

db:CNNVDid:CNNVD-200703-393

Trust: 0.7

db:BUGTRAQid:20070315 NORTON INSUFFICIENT VALIDATION OF 'SYMTDI' DRIVER INPUT BUFFER

Trust: 0.6

db:XFid:33003

Trust: 0.6

db:FULLDISCid:20070315 NORTON INSUFFICIENT VALIDATION OF 'SYMTDI' DRIVER

Trust: 0.6

db:PACKETSTORMid:59201

Trust: 0.2

db:SEEBUGid:SSVID-83226

Trust: 0.1

db:EXPLOIT-DBid:29743

Trust: 0.1

db:VULHUBid:VHN-24838

Trust: 0.1

sources: VULHUB: VHN-24838 // BID: 22977 // JVNDB: JVNDB-2007-005251 // PACKETSTORM: 59201 // CNNVD: CNNVD-200703-393 // NVD: CVE-2007-1476

REFERENCES

url:http://www.securityfocus.com/bid/22977

Trust: 1.7

url:http://www.symantec.com/avcenter/security/content/2007.09.05.html

Trust: 1.7

url:http://www.matousec.com/info/advisories/norton-insufficient-validation-of-symtdi-driver-input-buffer.php

Trust: 1.7

url:http://osvdb.org/35088

Trust: 1.7

url:http://securitytracker.com/id?1018656

Trust: 1.7

url:http://securityreason.com/securityalert/2438

Trust: 1.7

url:http://marc.info/?l=full-disclosure&m=117396596027148&w=2

Trust: 1.6

url:http://www.securityfocus.com/archive/1/462926/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/33003

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-1476

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-1476

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/33003

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/462926/100/0/threaded

Trust: 0.6

url:http://www.symantec.com

Trust: 0.3

url:/archive/1/462926

Trust: 0.3

url:http://securityresponse.symantec.com/avcenter/security/content/2007.09.05.html

Trust: 0.3

url:http://marc.info/?l=full-disclosure&m=117396596027148&w=2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2007-1476

Trust: 0.1

url:http://cve.mitre.org),

Trust: 0.1

sources: VULHUB: VHN-24838 // BID: 22977 // JVNDB: JVNDB-2007-005251 // PACKETSTORM: 59201 // CNNVD: CNNVD-200703-393 // NVD: CVE-2007-1476

CREDITS

David Matousekā€» david@matousec.com

Trust: 0.6

sources: CNNVD: CNNVD-200703-393

SOURCES

db:VULHUBid:VHN-24838
db:BIDid:22977
db:JVNDBid:JVNDB-2007-005251
db:PACKETSTORMid:59201
db:CNNVDid:CNNVD-200703-393
db:NVDid:CVE-2007-1476

LAST UPDATE DATE

2024-11-23T22:46:54.278000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-24838date:2018-10-16T00:00:00
db:BIDid:22977date:2007-09-06T18:01:00
db:JVNDBid:JVNDB-2007-005251date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200703-393date:2007-03-19T00:00:00
db:NVDid:CVE-2007-1476date:2024-11-21T00:28:24.377

SOURCES RELEASE DATE

db:VULHUBid:VHN-24838date:2007-03-16T00:00:00
db:BIDid:22977date:2007-03-15T00:00:00
db:JVNDBid:JVNDB-2007-005251date:2012-12-20T00:00:00
db:PACKETSTORMid:59201date:2007-09-10T21:29:54
db:CNNVDid:CNNVD-200703-393date:2007-03-16T00:00:00
db:NVDid:CVE-2007-1476date:2007-03-16T21:19:00