Vulnerability Description
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Antivirus | 10.0 |
| Symantec | Client Security | 3.0 |
| Symantec | Norton 360 | 1.0 |
| Symantec | Norton Antispam | 2004 |
| Symantec | Norton Antivirus | 2004 |
| Symantec | Norton Internet Security | 2004 |
| Symantec | Norton Personal Firewall | 2004 |
| Symantec | Norton System Works | 2004 |
Related Weaknesses (CWE)
References
- http://osvdb.org/34692
- http://secunia.com/advisories/24677Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2008.12.12.html
- http://www.matousec.com/info/advisories/Norton-Multiple-insufficient-argument-vaVendor Advisory
- http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php
- http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-se
- http://www.securityfocus.com/archive/1/464456/100/0/threaded
- http://www.securityfocus.com/archive/1/479830/100/0/threaded
- http://www.securityfocus.com/bid/23241Exploit
- http://www.securitytracker.com/id?1017837Patch
- http://www.securitytracker.com/id?1017838Patch
- http://www.securitytracker.com/id?1021386
- http://www.securitytracker.com/id?1021387
- http://www.securitytracker.com/id?1021388
- http://www.securitytracker.com/id?1021389
FAQ
What is CVE-2007-1793?
CVE-2007-1793 is a vulnerability with a CVSS score of 4.9 (MEDIUM). SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause ...
How severe is CVE-2007-1793?
CVE-2007-1793 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1793?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Antivirus, Symantec Client Security, Symantec Norton 360, Symantec Norton Antispam, Symantec Norton Antivirus.