CVE-2007-2403: Medium severity Apple iOS and macOS vulnerability
Published Aug 3, 2007
·Updated
CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.
Affected Software
5 affected components
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.10
Apple CFNetwork
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
10:17 AM
Data Sourced
10:17 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2403?
CVE-2007-2403 has been classified as a moderate severity vulnerability.
2
How is CVE-2007-2403 exploited?
CVE-2007-2403 can be exploited by remote attackers through the injection of arbitrary FTP commands via improperly validated ftp: URIs.
3
What versions of Mac OS X are affected by CVE-2007-2403?
CVE-2007-2403 affects Apple Mac OS X versions 10.3.9 and 10.4.10.
4
How do I fix CVE-2007-2403?
To fix CVE-2007-2403, users should apply the latest security updates released by Apple for their operating system.
5
What is CFNetwork in relation to CVE-2007-2403?
CFNetwork is the component in Mac OS X that is vulnerable in CVE-2007-2403, enabling transmission of FTP commands.