CVE-2007-0724

The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
References
Link Resource
http://docs.info.apple.com/article.html?artnum=305214
http://docs.info.apple.com/article.html?artnum=305391
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html Patch Vendor Advisory
http://secunia.com/advisories/24479
http://secunia.com/advisories/24966
http://www.osvdb.org/34855
http://www.securityfocus.com/bid/22948
http://www.securitytracker.com/id?1017751
http://www.securitytracker.com/id?1017942
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-109A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2007/1470
https://exchange.xforce.ibmcloud.com/vulnerabilities/32973
http://docs.info.apple.com/article.html?artnum=305214
http://docs.info.apple.com/article.html?artnum=305391
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html Patch Vendor Advisory
http://secunia.com/advisories/24479
http://secunia.com/advisories/24966
http://www.osvdb.org/34855
http://www.securityfocus.com/bid/22948
http://www.securitytracker.com/id?1017751
http://www.securitytracker.com/id?1017942
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-109A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2007/1470
https://exchange.xforce.ibmcloud.com/vulnerabilities/32973
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:26

Type Values Removed Values Added
References () http://docs.info.apple.com/article.html?artnum=305214 - () http://docs.info.apple.com/article.html?artnum=305214 -
References () http://docs.info.apple.com/article.html?artnum=305391 - () http://docs.info.apple.com/article.html?artnum=305391 -
References () http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html - () http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html -
References () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - Patch, Vendor Advisory () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - Patch, Vendor Advisory
References () http://secunia.com/advisories/24479 - () http://secunia.com/advisories/24479 -
References () http://secunia.com/advisories/24966 - () http://secunia.com/advisories/24966 -
References () http://www.osvdb.org/34855 - () http://www.osvdb.org/34855 -
References () http://www.securityfocus.com/bid/22948 - () http://www.securityfocus.com/bid/22948 -
References () http://www.securitytracker.com/id?1017751 - () http://www.securitytracker.com/id?1017751 -
References () http://www.securitytracker.com/id?1017942 - () http://www.securitytracker.com/id?1017942 -
References () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource
References () http://www.us-cert.gov/cas/techalerts/TA07-109A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-109A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/0930 - () http://www.vupen.com/english/advisories/2007/0930 -
References () http://www.vupen.com/english/advisories/2007/1470 - () http://www.vupen.com/english/advisories/2007/1470 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/32973 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/32973 -

Information

Published : 2007-03-13 22:19

Updated : 2024-11-21 00:26


NVD link : CVE-2007-0724

Mitre link : CVE-2007-0724

CVE.ORG link : CVE-2007-0724


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server