Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
BID:23241
Info
Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
| Bugtraq ID: | 23241 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-1793 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 01 2007 12:00AM |
| Updated: | Dec 11 2008 11:31PM |
| Credit: | David Matousek. |
| Vulnerable: |
Symantec Norton SystemWorks 2006 0 Symantec Norton SystemWorks 2005 Premier 0 Symantec Norton SystemWorks 2005 0 Symantec Norton SystemWorks 2004 Professional Edition Symantec Norton SystemWorks 2004 Symantec Norton System Works 2006 Symantec Norton System Works 2005 11.0.9 Symantec Norton System Works 2005 11.0 Symantec Norton System Works 2005 Premier Symantec Norton System Works 2005 0 Symantec Norton Personal Firewall 2006 9.1.1 .7 Symantec Norton Personal Firewall 2006 9.1 .33 Symantec Norton Internet Security 2008 0 Symantec Norton Internet Security 2007 0 Symantec Norton Internet Security 2006 Professional Edition Symantec Norton Internet Security 2006 0 Symantec Norton Internet Security 2005 Professional Edition Symantec Norton Internet Security 2005 Anti Spyware Edition 0 Symantec Norton Internet Security 2005 11.5.6 .14 Symantec Norton Internet Security 2005 11.0.9 Symantec Norton Internet Security 2005 11.0 Symantec Norton Internet Security 2005 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Antivirus 2008 0 Symantec Norton Antivirus 2007 0 Symantec Norton AntiVirus 2006 Symantec Norton AntiVirus 2005 Professional Edition Symantec Norton AntiVirus 2005 11.0 Symantec Norton AntiVirus 2005 Symantec Norton AntiVirus 2004 Professional Edition Symantec Norton AntiVirus 2004 Symantec Norton AntiSpam 2005 0 Symantec Norton AntiSpam 2004 Symantec Norton 360 1.0 Symantec Client Security 3.1.4 MR4 MP1 - build 4010 Symantec Client Security 3.1 .401 Symantec Client Security 3.1 .400 Symantec Client Security 3.1 .396 Symantec Client Security 3.1 .394 Symantec Client Security 3.0.2 .2021 Symantec Client Security 3.0.2 .2020 Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1 MR6 MP1 Symantec Client Security 3.1 MR6 Symantec Client Security 3.1 Symantec Client Security 3.0.1.1008 Symantec Client Security 3.0.1.1007 Symantec Client Security 3.0.1.1001 Symantec Client Security 3.0.1.1000 Symantec Client Security 3.0.0.359 Symantec AntiVirus Corporate Edition 10.1.4 MR4 MP1 - build 4010 Symantec AntiVirus Corporate Edition 10.1.4 Symantec AntiVirus Corporate Edition 10.1 .401 Symantec AntiVirus Corporate Edition 10.1 .400 Symantec AntiVirus Corporate Edition 10.1 .396 Symantec AntiVirus Corporate Edition 10.1 .394 Symantec AntiVirus Corporate Edition 10.0.2 .2021 Symantec AntiVirus Corporate Edition 10.0.2 .2020 Symantec AntiVirus Corporate Edition 10.0.2 .2011 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2002 Symantec AntiVirus Corporate Edition 10.0.2 .2001 Symantec AntiVirus Corporate Edition 10.0.2 .2000 Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 10.1.6.6000 Symantec AntiVirus Corporate Edition 10.1.6.600 Symantec AntiVirus Corporate Edition 10.1.4.4010 Symantec AntiVirus Corporate Edition 10.1 MR6 MP1 Symantec AntiVirus Corporate Edition 10.1 MR6 Symantec AntiVirus Corporate Edition 10.1 Symantec AntiVirus Corporate Edition 10.0.2.2000 Symantec AntiVirus Corporate Edition 10.0.1.1008 Symantec AntiVirus Corporate Edition 10.0.1.1007 Symantec AntiVirus Corporate Edition 10.0.1.1000 Symantec AntiVirus Corporate Edition 10.0.0.359 |
| Not Vulnerable: |
Symantec Client Security 3.1 MR7 Symantec AntiVirus Corporate Edition 10.1 MR7 |
Discussion
Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
Multiple Symantec products are prone to a local denial-of-service vulnerability.
This issue occurs when attackers supply invalid argument values to the 'SPBBCDrv.sys' driver.
A local attacker may exploit this issue to crash affected computers, denying service to legitimate users.
Multiple Symantec products are prone to a local denial-of-service vulnerability.
This issue occurs when attackers supply invalid argument values to the 'SPBBCDrv.sys' driver.
A local attacker may exploit this issue to crash affected computers, denying service to legitimate users.
Exploit / POC
Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
The following exploit code causes a denial-of-service condition:
The following exploit code causes a denial-of-service condition:
Solution / Fix
Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
Solution:
Vendor updates are available through 'LiveUpdate'.
Solution:
Vendor updates are available through 'LiveUpdate'.
References
Symantec Multiple Products SPBBCDrv Driver Local Denial of Service Vulnerability
References:
References:
- Norton Multiple insufficient argument validation of hooked SSDT function Vulnera (Matousec)
- Norton Personal Firewall Homepage (Symantec)
- Windows Personal Firewall Analysis (Matousec)
- Norton Multiple insufficient argument validation of hooked SSDT function Vulnera (Matousec)
- Plague in (security) software drivers & BSDOhook utility (Matousec)
- SYM08-022 Symantec SPBBCDRV.SYS Device Driver Local Denial of Service (Symantec)