CVE-2007-4680: Medium severity Apple iOS and macOS vulnerability
CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4680?
CVE-2007-4680 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2007-4680?
To fix CVE-2007-4680, update your Apple Mac OS X to version 10.4.11 or later as this version includes the necessary security patches.
What is affected by CVE-2007-4680?
CVE-2007-4680 affects Apple Mac OS X versions 10.3.9 and 10.4 through 10.4.10 due to improper SSL certificate validation.
What type of attack does CVE-2007-4680 enable?
CVE-2007-4680 enables remote attacks that can spoof trusted SSL certificates through a man-in-the-middle attack.
How can I verify if my system is vulnerable to CVE-2007-4680?
You can verify if your system is vulnerable to CVE-2007-4680 by checking the version of your Apple Mac OS X and ensuring it is updated to 10.4.11 or later.