Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-3673
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3673

Description:
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35347

ST
  1018372

SAID
  Secunia Advisory: SA26042

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=554

CONFIRM
  http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11d.html

BID
  22351


Return to the previous page.