CVE-2007-4686: High severity Apple iOS and macOS vulnerability
Published Nov 15, 2007
·Updated
Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request.
Affected Software
20 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Event History
Nov 15, 2007
CVE Published
01:46 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4686?
CVE-2007-4686 is classified as a denial of service vulnerability that can lead to system shutdown or privilege escalation.
2
How do I fix CVE-2007-4686?
To fix CVE-2007-4686, you should update to the latest version of Apple Mac OS X that addresses this vulnerability.
3
What systems are affected by CVE-2007-4686?
CVE-2007-4686 affects Apple Mac OS X versions 10.4 through 10.4.10, including Mac OS X Server.
4
Is it possible to exploit CVE-2007-4686 remotely?
CVE-2007-4686 requires local access to exploit, making remote exploitation unlikely.
5
What type of vulnerability is CVE-2007-4686?
CVE-2007-4686 is an integer signedness error vulnerability in the ttioctl function.