CVE-2007-3749: High severity Apple iOS and macOS vulnerability
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid program, then writing to the address space of the setuid process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3749?
CVE-2007-3749 is classified as a high severity vulnerability due to its ability to allow local users to execute arbitrary code.
How do I fix CVE-2007-3749?
To mitigate CVE-2007-3749, upgrade your Apple Mac OS X to version 10.4.11 or later.
Which versions of Mac OS X are affected by CVE-2007-3749?
CVE-2007-3749 affects Apple Mac OS X versions from 10.4 through 10.4.10.
Is CVE-2007-3749 exploitable remotely?
CVE-2007-3749 is not remotely exploitable; it requires local access to the system.
What types of attacks can CVE-2007-3749 facilitate?
CVE-2007-3749 can facilitate local attacks allowing unauthorized execution of code.