CVE-2007-1476
Summary
| CVE | CVE-2007-1476 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-16 21:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Client Security | 2.0 | All | All | All |
| Application | Symantec | Client Security | 2.0 | All | scf_7.1 | All |
| Application | Symantec | Client Security | 2.0 | build_9.0.0.338 | All | All |
| Application | Symantec | Client Security | 2.0 | build_9.0.0.338 | stm | All |
| Application | Symantec | Client Security | 2.0.1 | All | All | All |
| Application | Symantec | Client Security | 2.0.1_build_9.0.1.1000 | mr1 | All | All |
| Application | Symantec | Client Security | 2.0.2 | All | All | All |
| Application | Symantec | Client Security | 2.0.2_build_9.0.2.1000 | mr2 | All | All |
| Application | Symantec | Client Security | 2.0.3 | All | All | All |
| Application | Symantec | Client Security | 2.0.3_build_9.0.3.1000 | mr3 | All | All |
| Application | Symantec | Client Security | 2.0.4 | All | All | All |
| Application | Symantec | Client Security | 2.0.4 | mr4_build1000 | All | All |
| Application | Symantec | Client Security | 2.0.5 | All | All | All |
| Application | Symantec | Client Security | 2.0.5_build_1100 | All | All | All |
| Application | Symantec | Client Security | 2.0.5_build_1100_mp1 | mr5 | All | All |
| Application | Symantec | Client Security | 2.0.6 | All | All | All |
| Application | Symantec | Client Security | 2.0.6 | mr6 | All | All |
| Application | Symantec | Client Security | 2.0_scf_7.1 | All | All | All |
| Application | Symantec | Client Security | 2.0_stm_build_9.0.0.338 | All | All | All |
| Application | Symantec | Client Security | 2.1 | All | All | All |
| Application | Symantec | Client Security | 3.0 | All | All | All |
| Application | Symantec | Client Security | 3.0.0.359 | All | All | All |
| Application | Symantec | Client Security | 3.0.1.1000 | All | All | All |
| Application | Symantec | Client Security | 3.0.1.1001 | All | All | All |
| Application | Symantec | Client Security | 3.0.1.1007 | All | All | All |
| Application | Symantec | Client Security | 3.0.1.1008 | All | All | All |
| Application | Symantec | Client Security | 3.0.1.1009 | All | All | All |
| Application | Symantec | Client Security | 3.0.2 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2000 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2001 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2002 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2010 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2011 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2020 | All | All | All |
| Application | Symantec | Client Security | 3.0.2.2021 | All | All | All |
| Application | Symantec | Client Security | 3.1 | All | All | All |
| Application | Symantec | Client Security | 3.1.0.396 | All | All | All |
| Application | Symantec | Client Security | 3.1.0.401 | All | All | All |
| Application | Symantec | Client Security | 3.1.394 | All | All | All |
| Application | Symantec | Client Security | 3.1.396 | All | All | All |
| Application | Symantec | Client Security | 3.1.400 | All | All | All |
| Application | Symantec | Client Security | 3.1.401 | All | All | All |
| Application | Symantec | Norton Antispam | 2005 | All | All | All |
| Application | Symantec | Norton Antivirus | 10.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.1.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.1.1007 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.1.1008 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2001 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2002 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2010 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2011 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2020 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0.2.2021 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.394 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.396 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.4 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.4.4010 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.400 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.1.401 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 2005 | All | All | All |
| Application | Symantec | Norton Antivirus | 2006 | All | All | All |
| Application | Symantec | Norton Antivirus | 3.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.0.338 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1.1.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.3.1000 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.4 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.5 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.5.1100 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.6.1000 | All | corporate | All |
| Application | Symantec | Norton Internet Security | 2005 | All | All | All |
| Application | Symantec | Norton Internet Security | 2006 | All | All | All |
| Application | Symantec | Norton Personal Firewall | 2005 | All | All | All |
| Application | Symantec | Norton Personal Firewall | 2006 | All | All | All |
| Application | Symantec | Norton Personal Firewall | 2006_9.1.0.33 | All | All | All |
| Application | Symantec | Norton Personal Firewall | All | All | All | All |
| Application | Symantec | Norton System Works | 2005 | All | All | All |
| Application | Symantec | Norton System Works | 2006 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec SYMTDI.SYS Device Driver Local Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisory 2007-03-15.01 - matousec.com | af854a3a-2127-422b-91ae-364da2661108 | www.matousec.com | Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | |
| '[Full-disclosure] Norton Insufficient validation of 'SymTDI' driver' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Symantec Anti Virus SYMTDI.SYS IOCTL Validation Flaw Lets Local Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/35088 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.