CVE-2007-4702

The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:36

Type Values Removed Values Added
References () http://docs.info.apple.com/article.html?artnum=307004 - () http://docs.info.apple.com/article.html?artnum=307004 -
References () http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html - Patch () http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html - Patch
References () http://secunia.com/advisories/27695 - Vendor Advisory () http://secunia.com/advisories/27695 - Vendor Advisory
References () http://securitytracker.com/id?1018958 - () http://securitytracker.com/id?1018958 -
References () http://www.securityfocus.com/bid/26461 - () http://www.securityfocus.com/bid/26461 -
References () http://www.vupen.com/english/advisories/2007/3897 - () http://www.vupen.com/english/advisories/2007/3897 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/38506 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/38506 -

Information

Published : 2007-11-15 20:46

Updated : 2024-11-21 00:36


NVD link : CVE-2007-4702

Mitre link : CVE-2007-4702

CVE.ORG link : CVE-2007-4702


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server