CVE-2007-0747: High severity Apple iOS and macOS vulnerability
Published Apr 24, 2007
·Updated
loadwebdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
Affected Software
22 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Patch Available
Event History
Apr 24, 2007
CVE Published
05:19 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0747?
CVE-2007-0747 has a moderate severity as it allows local users to gain elevated privileges.
2
How do I fix CVE-2007-0747?
Fixing CVE-2007-0747 involves updating Apple Mac OS X to a version where the vulnerability has been addressed.
3
Which systems are affected by CVE-2007-0747?
CVE-2007-0747 affects Apple Mac OS X versions from 10.3.9 to 10.4.9.
4
Who can exploit CVE-2007-0747?
Local users with access to the affected systems can exploit CVE-2007-0747 by manipulating environment variables.
5
What component of Apple Mac OS X is vulnerable in CVE-2007-0747?
CVE-2007-0747 specifically affects the load_webdav function when mounting a WebDAV filesystem.