First published: Wed May 02 2007(Updated: )
ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alarm | =6.1.744.001 | |
Alarm | =6.5.737.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2467 has a high severity rating due to its ability to cause a denial of service by crashing the system.
To mitigate CVE-2007-2467, it is recommended to upgrade to the latest version of ZoneAlarm that addresses this vulnerability.
CVE-2007-2467 affects ZoneAlarm Pro versions 6.1.744.001, 6.5.737.000, and possibly earlier versions.
CVE-2007-2467 is classified as a local denial of service vulnerability due to improper input validation in the vsdatant device driver.
CVE-2007-2467 cannot be exploited remotely as it requires local user access to trigger the denial of service.