PT-2007-2194 · Apple · Macos X

Published

2007-04-24

·

Updated

2011-03-08

·

CVE-2007-0743

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Mac OS X versions 10.3.9 through 10.4.9
Description The issue allows local users to potentially obtain sensitive information, such as usernames and passwords, by listing processes. This is due to the URLMount feature passing credentials as command line arguments to the mount sub command.
Recommendations For Apple Mac OS X versions 10.3.9 through 10.4.9, consider restricting access to the mount sub command to minimize the risk of exploitation. As a temporary workaround, avoid using the URLMount feature for mounting filesystems on SMB servers until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0743

Affected Products

Macos X