Vulnerability Name: | CVE-2007-5829 (CCN-38229) | ||||||||
Assigned: | 2007-11-01 | ||||||||
Published: | 2007-11-01 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C) 5.2 Medium (Temporal CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Nov 02 2007 - 10:49:16 CDT Local Privilege Escalation in Norton AntiVirus for Mac Source: MITRE Type: CNA CVE-2007-5829 Source: OSVDB Type: UNKNOWN 40864 Source: CCN Type: SA27488 Symantec AntiVirus for Macintosh Privilege Escalation Weakness Source: SECUNIA Type: Vendor Advisory 27488 Source: CCN Type: SYM07-028 Symantec AntiVirus for Macintosh and Norton AntiVirus for Macintosh Local Elevation of Privilege Source: CONFIRM Type: UNKNOWN http://securityresponse.symantec.com/avcenter/security/Content/2007.11.02.html Source: CCN Type: SECTRACK ID: 1018889 Norton Anti-Virus for Macintosh Mount Scan Feature Lets Local Users Gain Root Privileges Source: SECTRACK Type: UNKNOWN 1018889 Source: CCN Type: SECTRACK ID: 1018890 Symantec Anti Virus for Macintosh Mount Scan Feature Lets Local Users Gain Root Privileges Source: SECTRACK Type: UNKNOWN 1018890 Source: CCN Type: OSVDB ID: 40864 Symantec AntiVirus for Macintosh Disk Mount Scanner Permission Weakness Local Privilege Escalation Source: BID Type: UNKNOWN 26253 Source: CCN Type: BID-26253 Symantec AntiVirus For Macintosh Mount Scan Local Privilege Escalation Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2007-3698 Source: XF Type: UNKNOWN symantec-av-mac-privilege-escalation(38229) Source: XF Type: UNKNOWN symantec-av-mac-privilege-escalation(38229) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |