Vulnerability Name: | CVE-2008-0046 (CCN-41317) | ||||||||
Assigned: | 2008-03-18 | ||||||||
Published: | 2008-03-18 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-0046 Source: CCN Type: Apple Web site About Security Update 2008-002 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=307562 Source: APPLE Type: Patch APPLE-SA-2008-03-18 Source: CCN Type: SA29420 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 29420 Source: CCN Type: SECTRACK ID: 1019658 Mac OS X Application Firewall German Language Preference Panel May Mislead Users and Incorrectly Permit Services to Accept Connections Source: CCN Type: OSVDB ID: 43375 Apple Mac OS X Application Firewall German Translation Configuration Weakness Source: BID Type: UNKNOWN 28304 Source: CCN Type: BID-28304 RETIRED: Apple Mac OS X 2008-002 Multiple Security Vulnerabilities Source: BID Type: UNKNOWN 28368 Source: CCN Type: BID-28368 Apple Mac OS X Application Firewall German Translation Insecure Configuration Weakness Source: SECTRACK Type: UNKNOWN 1019658 Source: CERT Type: US Government Resource TA08-079A Source: VUPEN Type: UNKNOWN ADV-2008-0924 Source: XF Type: UNKNOWN macos-applicationfirewall-weak-security(41317) Source: XF Type: UNKNOWN macos-applicationfirewall-weak-security(41317) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |