CVE-2007-4687: Critical severity Apple iOS and macOS vulnerability
The remotecmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4687?
CVE-2007-4687 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2007-4687?
To remediate CVE-2007-4687, it is recommended to secure the symbolic link or update to a patched version of Mac OS X that addresses this vulnerability.
What impact does CVE-2007-4687 have on my system?
CVE-2007-4687 allows tftpd users to escape the tftpboot private directory, potentially accessing arbitrary files on the system.
Which versions of Mac OS X are affected by CVE-2007-4687?
CVE-2007-4687 affects Apple Mac OS X versions from 10.4 through 10.4.10.
Is there a workaround for CVE-2007-4687?
Currently, no specific workaround is recommended for CVE-2007-4687 besides ensuring that the system is updated with the latest security patches.