Vulnerability Name: | CVE-2007-4679 (CCN-38462) | ||||||||
Assigned: | 2007-11-14 | ||||||||
Published: | 2007-11-14 | ||||||||
Updated: | 2018-10-26 | ||||||||
Summary: | CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4679 Source: CCN Type: Apple Web site About the security content of Mac OS X 10.4.11 and Security Update 2007-008 Source: CONFIRM Type: Vendor Advisory http://docs.info.apple.com/article.html?artnum=307041 Source: APPLE Type: Vendor Advisory APPLE-SA-2007-11-14 Source: CCN Type: SA27643 Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 27643 Source: CCN Type: SECTRACK ID: 1018950 Mac OS X Kernel and Networking Bugs Let Remote and Local Users Deny Service or Execute Arbitrary Code Source: SECTRACK Type: Third Party Advisory, VDB Entry 1018950 Source: CCN Type: OSVDB ID: 40684 Apple Mac OS X CFFTP FTP Server FTP PASV Arbitrary Site Client Redirect Source: BID Type: Third Party Advisory, VDB Entry 26444 Source: CCN Type: BID-26444 Apple Mac OS X v10.4.11 2007-008 Multiple Security Vulnerabilities Source: CERT Type: Third Party Advisory, US Government Resource TA07-319A Source: VUPEN Type: Third Party Advisory ADV-2007-3868 Source: XF Type: Third Party Advisory, VDB Entry macosx-cfftp-client-redirect(38462) Source: XF Type: UNKNOWN macosx-cfftp-client-redirect(38462) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |