First published: Fri Aug 03 2007(Updated: )
CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.4.10 | |
Apple macOS Server | =10.3.9 | |
Apple macOS Server | =10.4.10 | |
CFNetwork |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2403 has been classified as a moderate severity vulnerability.
CVE-2007-2403 can be exploited by remote attackers through the injection of arbitrary FTP commands via improperly validated ftp: URIs.
CVE-2007-2403 affects Apple Mac OS X versions 10.3.9 and 10.4.10.
To fix CVE-2007-2403, users should apply the latest security updates released by Apple for their operating system.
CFNetwork is the component in Mac OS X that is vulnerable in CVE-2007-2403, enabling transmission of FTP commands.