CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:N/I:N/A:P
AI Score
Confidence
High
EPSS
Percentile
9.7%
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver’s \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.
Vendor | Product | Version | CPE |
---|---|---|---|
symantec | client_security | 2.0 | cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:* |
symantec | client_security | 2.0 | cpe:2.3:a:symantec:client_security:2.0:*:scf_7.1:*:*:*:*:* |
symantec | client_security | 2.0 | cpe:2.3:a:symantec:client_security:2.0:build_9.0.0.338:*:*:*:*:*:* |
symantec | client_security | 2.0 | cpe:2.3:a:symantec:client_security:2.0:build_9.0.0.338:stm:*:*:*:*:* |
symantec | client_security | 2.0.1 | cpe:2.3:a:symantec:client_security:2.0.1:*:*:*:*:*:*:* |
symantec | client_security | 2.0.1_build_9.0.1.1000 | cpe:2.3:a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1:*:*:*:*:*:* |
symantec | client_security | 2.0.2 | cpe:2.3:a:symantec:client_security:2.0.2:*:*:*:*:*:*:* |
symantec | client_security | 2.0.2_build_9.0.2.1000 | cpe:2.3:a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2:*:*:*:*:*:* |
symantec | client_security | 2.0.3 | cpe:2.3:a:symantec:client_security:2.0.3:*:*:*:*:*:*:* |
symantec | client_security | 2.0.3_build_9.0.3.1000 | cpe:2.3:a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3:*:*:*:*:*:* |
marc.info/?l=full-disclosure&m=117396596027148&w=2
osvdb.org/35088
securityreason.com/securityalert/2438
securitytracker.com/id?1018656
www.matousec.com/info/advisories/Norton-Insufficient-validation-of-SymTDI-driver-input-buffer.php
www.securityfocus.com/archive/1/462926/100/0/threaded
www.securityfocus.com/bid/22977
www.symantec.com/avcenter/security/Content/2007.09.05.html
exchange.xforce.ibmcloud.com/vulnerabilities/33003