The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other applications to access the key without warning the user, which might allow other applications to bypass intended access restrictions.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://docs.info.apple.com/article.html?artnum=307041 - | |
References | () http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html - Patch | |
References | () http://secunia.com/advisories/27643 - Vendor Advisory | |
References | () http://securitytracker.com/id?1018948 - | |
References | () http://www.securityfocus.com/bid/26444 - | |
References | () http://www.us-cert.gov/cas/techalerts/TA07-319A.html - US Government Resource | |
References | () http://www.vupen.com/english/advisories/2007/3868 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38485 - |
Information
Published : 2007-11-15 02:46
Updated : 2024-11-21 00:36
NVD link : CVE-2007-4699
Mitre link : CVE-2007-4699
CVE.ORG link : CVE-2007-4699
JSON object : View
Products Affected
apple
- mac_os_x
- safari
- mac_os_x_server
CWE
CWE-264
Permissions, Privileges, and Access Controls