Symantec Client Firewall Products SYMNDIS.SYS Driver Remote Denial Of Service Vulnerability
10 Apr. 2012
Summary
This allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.
Vulnerable Systems:
* Symantec Norton Personal Firewall 2004
* Symantec Norton Personal Firewall 2003
* Symantec Norton Internet Security 2004 Professional Edition
* Symantec Norton Internet Security 2004
* Symantec Norton Internet Security 2003 Professional Edition
* Symantec Norton Internet Security 2003
* Symantec Client Security 1.1
* Symantec Client Security 1.0
* Symantec Client Firewall 5.1.1
* Symantec Client Firewall 5.0 1
Symantec Client Firewall has been reported to be prone to a remote denial of service vulnerability. The issue is reported to present itself in the TCP packet processing routines of the affected software.
It is reported that this vulnerability will have a system wide impact, causing Windows GUI and peripherals that are attached to the host to become unresponsive. A hard reset is reported to be required to restore normal functionality to the system.
Vendor Status:
Symantec as issued an update for this vulnerablity