CVE-2007-4703
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=307004Patch
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.htmlPatch
- http://secunia.com/advisories/27695Vendor Advisory
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26460
- http://www.vupen.com/english/advisories/2007/3897Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38479
- http://docs.info.apple.com/article.html?artnum=307004Patch
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.htmlPatch
- http://secunia.com/advisories/27695Vendor Advisory
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26460
- http://www.vupen.com/english/advisories/2007/3897Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38479
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.