PT-2007-5860 · Apple · Macos X

Published

2007-11-15

·

Updated

2017-07-29

·

CVE-2007-4702

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apple Mac OS X version 10.5
Description: The issue concerns the Application Firewall in Apple Mac OS X, where enabling "Block all incoming connections" does not effectively block connections for root processes or mDNSResponder, potentially allowing remote attackers or local root processes to bypass intended access restrictions.
Recommendations: For Apple Mac OS X version 10.5, consider disabling the "Block all incoming connections" feature and instead implement more specific, restrictive firewall rules to minimize the risk of unauthorized access. Additionally, restrict access to root processes and mDNSResponder to prevent potential exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4702

Affected Products

Macos X