CVE-2007-4702
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.25% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=307004
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.htmlPatch
- http://secunia.com/advisories/27695Vendor Advisory
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26461
- http://www.vupen.com/english/advisories/2007/3897
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38506
- http://docs.info.apple.com/article.html?artnum=307004
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.htmlPatch
- http://secunia.com/advisories/27695Vendor Advisory
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26461
- http://www.vupen.com/english/advisories/2007/3897
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38506
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.