ID

VAR-200704-0544


CVE

CVE-2007-1793


TITLE

Symantec Norton Personal Firewall of SPBBCDrv.sys Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2007-005331

DESCRIPTION

SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected. Multiple Symantec products are prone to a local denial-of-service vulnerability. This issue occurs when attackers supply invalid argument values to the 'SPBBCDrv.sys' driver. A local attacker may exploit this issue to crash affected computers, denying service to legitimate users. Symantec Norton Personal Firewall is a very popular firewall software. There is a loophole in the driver implementation of Norton Personal Firewall, and local attackers may use this loophole to perform denial-of-service attacks on the system. The vulnerability is caused due to an input validation error in SPBBCDrv.sys when handling parameters of certain hooked functions. This can be exploited to crash the system by calling NtCreateMutant or NtOpenEvent with specially crafted parameters. The vulnerability is confirmed in version 9.0.0.73 and also reported in versions 9.1.1.7 and 9.1.0.33. Other versions may also be affected. SOLUTION: Restrict access to trusted users only. PROVIDED AND/OR DISCOVERED BY: Matousec Transparent Security ORIGINAL ADVISORY: Matousec Transparent Security: http://www.matousec.com/info/advisories/Norton-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2007-1793 // JVNDB: JVNDB-2007-005331 // BID: 23241 // VULHUB: VHN-25155 // PACKETSTORM: 55533

AFFECTED PRODUCTS

vendor:symantecmodel:client securityscope:eqversion:3.1

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.394

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.400

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.396

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2020

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2011

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2021

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.401

Trust: 1.9

vendor:symantecmodel:client securityscope:eqversion:3.1.0.396

Trust: 1.6

vendor:symantecmodel:client securityscope:eqversion:3.1.0.401

Trust: 1.6

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1008

Trust: 1.3

vendor:symantecmodel:norton antispamscope:eqversion:2004

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:2004

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.0.359

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1001

Trust: 1.3

vendor:symantecmodel:norton internet securityscope:eqversion:2004

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:2006

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2000

Trust: 1.3

vendor:symantecmodel:norton antivirusscope:eqversion:2005

Trust: 1.3

vendor:symantecmodel:norton internet securityscope:eqversion:2005

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1000

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2010

Trust: 1.3

vendor:symantecmodel:norton system worksscope:eqversion:2006

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2001

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1007

Trust: 1.3

vendor:symantecmodel:client securityscope:eqversion:3.0.2.2002

Trust: 1.3

vendor:symantecmodel:antivirusscope:eqversion:10.0.2.1

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.6

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:3.0.2

Trust: 1.0

vendor:symantecmodel:norton 360scope:eqversion:1.0

Trust: 1.0

vendor:symantecmodel:norton internet securityscope:eqversion:2006

Trust: 1.0

vendor:symantecmodel:norton system worksscope:eqversion:2005

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.1

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.9

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.2.2

Trust: 1.0

vendor:symantecmodel:norton system worksscope:eqversion:2004

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.1.1

Trust: 1.0

vendor:symantecmodel:norton antispamscope:eqversion:2005

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.7

Trust: 1.0

vendor:symantecmodel:client securityscope:eqversion:3.0.1.1009

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2006_9.1.0.33

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.8

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2006

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.2

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2006_9.1.1.7

Trust: 1.0

vendor:symantecmodel:norton internet securityscope:eqversion:2007

Trust: 1.0

vendor:symantecmodel:norton internet securityscope:eqversion:2008

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2005

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:2007

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.3

Trust: 1.0

vendor:symantecmodel:norton antivirusscope:eqversion:2008

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.4

Trust: 1.0

vendor:symantecmodel:norton personal firewallscope:eqversion:2004

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0.5

Trust: 1.0

vendor:symantecmodel:antivirusscope:eqversion:10.0

Trust: 1.0

vendor:symantecmodel:client securityscope: - version: -

Trust: 0.8

vendor:symantecmodel:norton 360scope: - version: -

Trust: 0.8

vendor:symantecmodel:norton antispamscope: - version: -

Trust: 0.8

vendor:symantecmodel:norton antivirusscope: - version: -

Trust: 0.8

vendor:symantecmodel:norton internet securityscope:eqversion:2008 15.0.0.60 and 2006 other up to

Trust: 0.8

vendor:symantecmodel:norton personal firewallscope:eqversion:2006 9.1.0.33 and 9.1.1.7

Trust: 0.8

vendor:symantecmodel:norton systemworksscope: - version: -

Trust: 0.8

vendor:symantecmodel:antivirusscope: - version: -

Trust: 0.8

vendor:symantecmodel:client securityscope:eqversion:3.1.6.6000

Trust: 0.3

vendor:symantecmodel:norton systemworksscope:eqversion:20060

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2010

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:20060

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1007

Trust: 0.3

vendor:symantecmodel:norton personal firewallscope:eqversion:20069.1.1.7

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:200511.5.6.14

Trust: 0.3

vendor:symantecmodel:norton antivirus professional editionscope:eqversion:2005

Trust: 0.3

vendor:symantecmodel:norton systemworksscope:eqversion:2004

Trust: 0.3

vendor:symantecmodel:norton systemworks premierscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.394

Trust: 0.3

vendor:symantecmodel:norton internet security anti spyware editionscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.6.600

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.6.6000

Trust: 0.3

vendor:symantecmodel:norton systemworksscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr7scope:neversion:10.1

Trust: 0.3

vendor:symantecmodel:norton internet security professional editionscope:eqversion:2006

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2001

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.400

Trust: 0.3

vendor:symantecmodel:client security mr6scope:eqversion:3.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr6 mp1scope:eqversion:10.1

Trust: 0.3

vendor:symantecmodel:norton system worksscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.401

Trust: 0.3

vendor:symantecmodel:client security mr4 mp1 buildscope:eqversion:3.1.4-4010

Trust: 0.3

vendor:symantecmodel:norton internet security professional editionscope:eqversion:2005

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.396

Trust: 0.3

vendor:symantecmodel:norton antivirusscope:eqversion:200511.0

Trust: 0.3

vendor:symantecmodel:norton antivirusscope:eqversion:20070

Trust: 0.3

vendor:symantecmodel:nortonscope:eqversion:3601.0

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:200511.0

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:20080

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2000

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.4.4010

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:200511.0.9

Trust: 0.3

vendor:symantecmodel:norton systemworks professional editionscope:eqversion:2004

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0

Trust: 0.3

vendor:symantecmodel:norton antivirus professional editionscope:eqversion:2004

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2020

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1000

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr6scope:eqversion:10.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1.4

Trust: 0.3

vendor:symantecmodel:norton personal firewallscope:eqversion:20069.1.33

Trust: 0.3

vendor:symantecmodel:norton system works premierscope:eqversion:2005

Trust: 0.3

vendor:symantecmodel:norton antivirusscope:eqversion:20080

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.1.1008

Trust: 0.3

vendor:symantecmodel:client security mr7scope:neversion:3.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2002

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.1

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2011

Trust: 0.3

vendor:symantecmodel:norton system worksscope:eqversion:200511.0

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.2.2021

Trust: 0.3

vendor:symantecmodel:norton antispamscope:eqversion:20050

Trust: 0.3

vendor:symantecmodel:norton internet security professional editionscope:eqversion:2004

Trust: 0.3

vendor:symantecmodel:antivirus corporate editionscope:eqversion:10.0.0.359

Trust: 0.3

vendor:symantecmodel:norton system worksscope:eqversion:200511.0.9

Trust: 0.3

vendor:symantecmodel:antivirus corporate edition mr4 mp1 buildscope:eqversion:10.1.4-4010

Trust: 0.3

vendor:symantecmodel:norton internet securityscope:eqversion:20070

Trust: 0.3

vendor:symantecmodel:client security mr6 mp1scope:eqversion:3.1

Trust: 0.3

sources: BID: 23241 // JVNDB: JVNDB-2007-005331 // CNNVD: CNNVD-200704-033 // NVD: CVE-2007-1793

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-1793
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-1793
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200704-033
value: MEDIUM

Trust: 0.6

VULHUB: VHN-25155
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-1793
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-25155
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-25155 // JVNDB: JVNDB-2007-005331 // CNNVD: CNNVD-200704-033 // NVD: CVE-2007-1793

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-25155 // JVNDB: JVNDB-2007-005331 // NVD: CVE-2007-1793

THREAT TYPE

local

Trust: 1.0

sources: BID: 23241 // PACKETSTORM: 55533 // CNNVD: CNNVD-200704-033

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200704-033

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-005331

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-25155

PATCH

title:SYM08-022url:http://www.symantec.com/avcenter/security/Content/2008.12.12.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-005331

EXTERNAL IDS

db:NVDid:CVE-2007-1793

Trust: 2.8

db:BIDid:23241

Trust: 2.0

db:SECUNIAid:24677

Trust: 1.8

db:SECTRACKid:1021388

Trust: 1.7

db:SECTRACKid:1017837

Trust: 1.7

db:SECTRACKid:1021386

Trust: 1.7

db:SECTRACKid:1017838

Trust: 1.7

db:SECTRACKid:1021387

Trust: 1.7

db:SECTRACKid:1021389

Trust: 1.7

db:VUPENid:ADV-2007-1192

Trust: 1.7

db:OSVDBid:34692

Trust: 1.7

db:JVNDBid:JVNDB-2007-005331

Trust: 0.8

db:CNNVDid:CNNVD-200704-033

Trust: 0.7

db:XFid:33352

Trust: 0.6

db:BUGTRAQid:20070918 PLAGUE IN (SECURITY) SOFTWARE DRIVERS & BSDOHOOK UTILITY

Trust: 0.6

db:BUGTRAQid:20070401 NORTON MULTIPLE INSUFFICIENT ARGUMENT VALIDATION OF HOOKED SSDT FUNCTION VULNERABILITY

Trust: 0.6

db:SEEBUGid:SSVID-83289

Trust: 0.1

db:EXPLOIT-DBid:29810

Trust: 0.1

db:VULHUBid:VHN-25155

Trust: 0.1

db:PACKETSTORMid:55533

Trust: 0.1

sources: VULHUB: VHN-25155 // BID: 23241 // JVNDB: JVNDB-2007-005331 // PACKETSTORM: 55533 // CNNVD: CNNVD-200704-033 // NVD: CVE-2007-1793

REFERENCES

url:http://www.matousec.com/info/advisories/norton-multiple-insufficient-argument-validation-of-hooked-ssdt-functions.php

Trust: 2.1

url:http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php

Trust: 2.0

url:http://www.securityfocus.com/bid/23241

Trust: 1.7

url:http://securityresponse.symantec.com/avcenter/security/content/2008.12.12.html

Trust: 1.7

url:http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php

Trust: 1.7

url:http://osvdb.org/34692

Trust: 1.7

url:http://www.securitytracker.com/id?1017837

Trust: 1.7

url:http://www.securitytracker.com/id?1017838

Trust: 1.7

url:http://www.securitytracker.com/id?1021386

Trust: 1.7

url:http://www.securitytracker.com/id?1021387

Trust: 1.7

url:http://www.securitytracker.com/id?1021388

Trust: 1.7

url:http://www.securitytracker.com/id?1021389

Trust: 1.7

url:http://secunia.com/advisories/24677

Trust: 1.7

url:http://www.securityfocus.com/archive/1/464456/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/479830/100/0/threaded

Trust: 1.1

url:http://www.vupen.com/english/advisories/2007/1192

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/33352

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-1793

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-1793

Trust: 0.8

url:http://www.frsirt.com/english/advisories/2007/1192

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/33352

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/479830/100/0/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/464456/100/0/threaded

Trust: 0.6

url:http://www.symantec.com/sabu/nis/npf/

Trust: 0.3

url:/archive/1/464456

Trust: 0.3

url:/archive/1/479830

Trust: 0.3

url:http://www.symantec.com/avcenter/security/content/2008.12.12.html

Trust: 0.3

url:http://secunia.com/product/6638/

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/disassembling_og_reversing/

Trust: 0.1

url:http://secunia.com/secunia_vacancies/

Trust: 0.1

url:http://secunia.com/hardcore_disassembler_and_reverse_engineer/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/linux_security_specialist/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:http://secunia.com/advisories/24677/

Trust: 0.1

sources: VULHUB: VHN-25155 // BID: 23241 // JVNDB: JVNDB-2007-005331 // PACKETSTORM: 55533 // CNNVD: CNNVD-200704-033 // NVD: CVE-2007-1793

CREDITS

David Matousekā€» david@matousec.com

Trust: 0.6

sources: CNNVD: CNNVD-200704-033

SOURCES

db:VULHUBid:VHN-25155
db:BIDid:23241
db:JVNDBid:JVNDB-2007-005331
db:PACKETSTORMid:55533
db:CNNVDid:CNNVD-200704-033
db:NVDid:CVE-2007-1793

LAST UPDATE DATE

2024-11-23T21:48:52.007000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-25155date:2018-10-16T00:00:00
db:BIDid:23241date:2008-12-11T23:31:00
db:JVNDBid:JVNDB-2007-005331date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200704-033date:2009-02-06T00:00:00
db:NVDid:CVE-2007-1793date:2024-11-21T00:29:10.343

SOURCES RELEASE DATE

db:VULHUBid:VHN-25155date:2007-04-02T00:00:00
db:BIDid:23241date:2007-04-01T00:00:00
db:JVNDBid:JVNDB-2007-005331date:2012-12-20T00:00:00
db:PACKETSTORMid:55533date:2007-04-02T23:13:40
db:CNNVDid:CNNVD-200704-033date:2007-04-02T00:00:00
db:NVDid:CVE-2007-1793date:2007-04-02T22:19:00