PT-2007-5861 · Apple · Macos X

Published

2007-11-15

·

Updated

2017-07-29

·

CVE-2007-4703

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apple Mac OS X version 10.5
Description: The issue concerns the Application Firewall in Apple Mac OS X, which fails to prevent a root process from accepting incoming connections. This occurs even when the "Block incoming connections" option has been set for its associated executable, potentially allowing remote attackers or local root processes to bypass intended access restrictions.
Recommendations: For Apple Mac OS X version 10.5, consider disabling the executable associated with the vulnerable Application Firewall setting until a patch is available, or apply specific configuration changes to restrict incoming connections for root processes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4703

Affected Products

Macos X