PT-2007-5861 · Apple · Macos X
Published
2007-11-15
·
Updated
2017-07-29
·
CVE-2007-4703
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apple Mac OS X version 10.5
Description:
The issue concerns the Application Firewall in Apple Mac OS X, which fails to prevent a root process from accepting incoming connections. This occurs even when the "Block incoming connections" option has been set for its associated executable, potentially allowing remote attackers or local root processes to bypass intended access restrictions.
Recommendations:
For Apple Mac OS X version 10.5, consider disabling the executable associated with the vulnerable Application Firewall setting until a patch is available, or apply specific configuration changes to restrict incoming connections for root processes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X