CVE-2007-4702: Critical severity Apple iOS and macOS vulnerability
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4702?
CVE-2007-4702 has a moderate severity level due to its potential to allow bypassing access controls.
How do I fix CVE-2007-4702?
To mitigate CVE-2007-4702, users should disable the 'Block all incoming connections' setting in the Application Firewall.
What systems are affected by CVE-2007-4702?
CVE-2007-4702 affects Apple Mac OS X 10.5 and Apple Mac OS X Server 10.5.
What are the risks associated with CVE-2007-4702?
The primary risk of CVE-2007-4702 is that it allows unauthorized incoming connections to root processes, compromising system security.
Can CVE-2007-4702 be exploited remotely?
Yes, CVE-2007-4702 can potentially be exploited remotely by attackers if certain conditions are met.