Vulnerabilities > CVE-2007-4703 - Unspecified vulnerability in Apple mac OS X and mac OS X Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_10_5_1.NASL |
description | The remote host is running a version of Mac OS X 10.5.x that is prior to 10.5.1. This update contains several security fixes for the application Firewall. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 28252 |
published | 2007-11-16 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/28252 |
title | Mac OS X 10.5.x < 10.5.1 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 26460 CVE(CAN) ID: CVE-2007-4703 Apple Mac OS X是苹果家族机器所使用的操作系统。 Mac OS X应用防火墙的实现上存在漏洞,可能导致非授权的网络访问。 Mac OS X应用防火墙的“设置特定服务和应用程序的访问”设置没有正确地实施安全策略,即使已经将可执行程序明确的添加到了程序列表中并标记为“阻断所有入站连接”,以root用户权限(UID 0)运行的进程仍可接收入站连接,这可能导致非预期的暴露某些网络服务,攻击者可以执行各种网络攻击入侵系统。 Apple Mac OS X 10.5 Apple MacOS X Server 10.5 Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16133&cat=60&platform=osx&method=sa/MacOSXUpd10.5.1.dmg" target="_blank">http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16133&cat=60&platform=osx&method=sa/MacOSXUpd10.5.1.dmg</a> <a href="http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16134&cat=60&platform=osx&method=sa/MacOSXServerUpd10.5.1.dmg" target="_blank">http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16134&cat=60&platform=osx&method=sa/MacOSXServerUpd10.5.1.dmg</a> |
id | SSV:2430 |
last seen | 2017-11-19 |
modified | 2007-11-17 |
published | 2007-11-17 |
reporter | Root |
title | Apple Mac OS X应用防火墙非授权网络访问漏洞 |
References
- http://docs.info.apple.com/article.html?artnum=307004
- http://docs.info.apple.com/article.html?artnum=307004
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html
- http://secunia.com/advisories/27695
- http://secunia.com/advisories/27695
- http://securitytracker.com/id?1018958
- http://securitytracker.com/id?1018958
- http://www.securityfocus.com/bid/26460
- http://www.securityfocus.com/bid/26460
- http://www.vupen.com/english/advisories/2007/3897
- http://www.vupen.com/english/advisories/2007/3897
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38479