CVE-2007-4691: Critical severity Apple iOS and macOS vulnerability
The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4691?
CVE-2007-4691 is considered a medium severity vulnerability due to its potential to allow unauthorized file system access.
How do I fix CVE-2007-4691?
To fix CVE-2007-4691, it is recommended to update to the latest version of macOS that addresses this vulnerability.
What systems are affected by CVE-2007-4691?
CVE-2007-4691 affects Apple Mac OS X versions 10.4 through 10.4.10 and Apple Mac OS X Server versions 10.3.9 to 10.4.10.
What kind of attack does CVE-2007-4691 enable?
CVE-2007-4691 allows attackers to bypass intended restrictions on local file system URLs through case-sensitive comparisons.
Is there a patch for CVE-2007-4691?
Yes, Apple has released patches that fix CVE-2007-4691, which should be applied to affected systems.