CVE-2007-1495: Medium severity Symantec Norton Personal Firewall vulnerability
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1495?
CVE-2007-1495 is classified as a denial of service vulnerability.
How do I fix CVE-2007-1495?
To mitigate CVE-2007-1495, users should update Symantec Norton Personal Firewall to a version that addresses this vulnerability.
What products are affected by CVE-2007-1495?
CVE-2007-1495 affects Symantec Norton Personal Firewall 2006 version 9.1.1.7 and potentially other products using the symevent.sys driver version 12.0.0.20.
Can CVE-2007-1495 be exploited remotely?
CVE-2007-1495 requires local access to exploit the vulnerability.
What are the potential impacts of CVE-2007-1495?
Exploitation of CVE-2007-1495 may lead to a system crash or denial of service.