CVE-2007-4269: Buffer Overflow
Published Nov 15, 2007
·Updated
Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.
Affected Software
23 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple Mac OS X Server=10.4.0
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Event History
Nov 15, 2007
CVE Published
01:46 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4269?
CVE-2007-4269 has a medium severity rating due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2007-4269?
To fix CVE-2007-4269, update your Apple Mac OS X to version 10.4.11 or later.
3
Who is affected by CVE-2007-4269?
CVE-2007-4269 affects local users running Apple Mac OS X versions 10.4 through 10.4.10.
4
What causes CVE-2007-4269?
CVE-2007-4269 is caused by an integer overflow in the Networking component when handling crafted AppleTalk Session Protocol messages.
5
Can CVE-2007-4269 be exploited remotely?
No, CVE-2007-4269 can only be exploited by local users on the affected systems.