CVE-2007-2404: XSS
Published Aug 3, 2007
·Updated
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
Affected Software
42 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.7
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.3.6
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.8
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.3.8
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.3.3
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.3
Apple Mac OS X Server=10.3.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
10:17 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2404?
CVE-2007-2404 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2007-2404?
To fix CVE-2007-2404, update your system to a version of Mac OS X that addresses this vulnerability.
3
What systems are affected by CVE-2007-2404?
CVE-2007-2404 affects Apple Mac OS X versions 10.3.1 through 10.4.10.
4
What kind of attack can exploit CVE-2007-2404?
CVE-2007-2404 can be exploited to perform HTTP response splitting attacks.
5
What is the impact of CVE-2007-2404?
The impact of CVE-2007-2404 includes the potential for attackers to inject arbitrary HTTP headers.