Vulnerability Name: | CVE-2007-4702 (CCN-38506) | ||||||||
Assigned: | 2007-11-15 | ||||||||
Published: | 2007-11-15 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4702 Source: CCN Type: Apple Web site About the security content of the Mac OS X 10.5.1 Update (client and server) Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=307004 Source: APPLE Type: Patch APPLE-SA-2007-11-15 Source: CCN Type: SA27695 Apple Mac OS X Application Firewall Weaknesses and Security Issue Source: SECUNIA Type: Vendor Advisory 27695 Source: CCN Type: SECTRACK ID: 1018958 Mac OS X Application Firewall Bugs May Let Remote Users Access the Services on the Target System Source: SECTRACK Type: UNKNOWN 1018958 Source: CCN Type: OSVDB ID: 40689 Apple Mac OS X Application Firewall "Block All Incoming Connections" Bypass Source: BID Type: UNKNOWN 26461 Source: CCN Type: BID-26461 Apple Mac OS X 10.5 Application Firewall Misleading Configuration Weakness Source: VUPEN Type: UNKNOWN ADV-2007-3897 Source: XF Type: UNKNOWN macosx-appfw-connect-bypass(38506) Source: XF Type: UNKNOWN macosx-appfw-connect-bypass(38506) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |