PT-2007-6793 · Norton+1 · Norton Antivirus For Macintosh+2

Publicado

2007-11-05

·

Atualizado

2017-07-29

·

CVE-2007-5829

CVSS v2.0

6.0

Média

VetorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec AntiVirus for Macintosh versions 9.x through 10.x Norton AntiVirus for Macintosh versions 10.0 through 10.1 Norton Internet Security for Macintosh versions 3.x
Description The issue concerns a weakness in the Disk Mount scanner's directory permissions, which are group writable. This weakness can be exploited by local admin users to gain root privileges. The exploitation occurs when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled, allowing the replacement of unspecified files that are executed during this process.
Recommendations For Symantec AntiVirus for Macintosh versions 9.x through 10.x, consider disabling the "Show Progress During Mount Scans" option to minimize the risk of exploitation. For Norton AntiVirus for Macintosh versions 10.0 through 10.1, restrict access to the directory used by the Disk Mount scanner to prevent unauthorized file replacements. For Norton Internet Security for Macintosh versions 3.x, avoid using the Disk Mount scanner feature until a fix is applied, and ensure that physical access to the system is strictly controlled.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5829

Produtos afetados

Norton Antivirus For Macintosh
Norton Internet Security For Macintosh
Symantec Antivirus For Macintosh