Vulnerability Name: | CVE-2007-4703 (CCN-38479) | ||||||||
Assigned: | 2007-11-15 | ||||||||
Published: | 2007-11-15 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4703 Source: CCN Type: Apple Web site About the security content of the Mac OS X 10.5.1 Update (client and server) Source: CONFIRM Type: Patch http://docs.info.apple.com/article.html?artnum=307004 Source: APPLE Type: Patch APPLE-SA-2007-11-15 Source: CCN Type: SA27695 Apple Mac OS X Application Firewall Weaknesses and Security Issue Source: SECUNIA Type: Vendor Advisory 27695 Source: CCN Type: SECTRACK ID: 1018958 Mac OS X Application Firewall Bugs May Let Remote Users Access the Services on the Target System Source: SECTRACK Type: UNKNOWN 1018958 Source: CCN Type: OSVDB ID: 40690 Apple Mac OS X Application Firewall Root Process Connection Restriction Bypass Source: BID Type: UNKNOWN 26460 Source: CCN Type: BID-26460 Apple Mac OS X Application Firewall Unauthorized Network Access Weakness Source: VUPEN Type: Vendor Advisory ADV-2007-3897 Source: XF Type: UNKNOWN macosx-appfw-rootuid-bypass(38479) Source: XF Type: UNKNOWN macosx-appfw-rootuid-bypass(38479) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |