Vulnerabilities > CVE-2007-4702 - Unspecified vulnerability in Apple mac OS X and mac OS X Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_10_5_1.NASL |
description | The remote host is running a version of Mac OS X 10.5.x that is prior to 10.5.1. This update contains several security fixes for the application Firewall. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 28252 |
published | 2007-11-16 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/28252 |
title | Mac OS X 10.5.x < 10.5.1 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 26461 CVE(CAN) ID: CVE-2007-4702 Apple Mac OS X是苹果家族机器所使用的操作系统。 Mac OS X的应用防火墙设置存在误导性的功能描述,可能由于错误的安全认识导致信息泄露。 Mac OS X的应用防火墙的“阻断所有入站连接”设置允许任何以root用户权限(UID 0)运行的进程接收入站连接,也允许mDNSResponder接收连接,这可能导致非预期的暴露网络服务,远程攻击者可以破坏防火墙的安全策略执行某些网络攻击。 Apple Mac OS X 10.5 Apple MacOS X Server 10.5 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16133&cat=60&platform=osx&method=sa/MacOSXUpd10.5.1.dmg" target="_blank">http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16133&cat=60&platform=osx&method=sa/MacOSXUpd10.5.1.dmg</a> <a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16134&cat=60&platform=osx&method=sa/MacOSXServerUpd10.5.1.dmg" target="_blank">http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16134&cat=60&platform=osx&method=sa/MacOSXServerUpd10.5.1.dmg</a> |
id | SSV:2429 |
last seen | 2017-11-19 |
modified | 2007-11-17 |
published | 2007-11-17 |
reporter | Root |
title | Apple Mac OS X防火墙误导性配置漏洞 |
References
- http://docs.info.apple.com/article.html?artnum=307004
- http://docs.info.apple.com/article.html?artnum=307004
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html
- http://secunia.com/advisories/27695
- http://secunia.com/advisories/27695
- http://securitytracker.com/id?1018958
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26461
- http://www.securityfocus.com/bid/26461
- http://www.vupen.com/english/advisories/2007/3897
- http://www.vupen.com/english/advisories/2007/3897
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38506
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38506