CVE-2007-4687: Critical severity Apple iOS and macOS vulnerability

Published Nov 15, 2007
·
Updated

The remotecmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.

Affected Software

20 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2

Event History

Nov 15, 2007
CVE Published
01:46 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-4687?

CVE-2007-4687 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive files.

2

How do I fix CVE-2007-4687?

To remediate CVE-2007-4687, it is recommended to secure the symbolic link or update to a patched version of Mac OS X that addresses this vulnerability.

3

What impact does CVE-2007-4687 have on my system?

CVE-2007-4687 allows tftpd users to escape the tftpboot private directory, potentially accessing arbitrary files on the system.

4

Which versions of Mac OS X are affected by CVE-2007-4687?

CVE-2007-4687 affects Apple Mac OS X versions from 10.4 through 10.4.10.

5

Is there a workaround for CVE-2007-4687?

Currently, no specific workaround is recommended for CVE-2007-4687 besides ensuring that the system is updated with the latest security patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203