First published: Thu Nov 15 2007(Updated: )
The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5 | |
Apple macOS Server | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4702 has a moderate severity level due to its potential to allow bypassing access controls.
To mitigate CVE-2007-4702, users should disable the 'Block all incoming connections' setting in the Application Firewall.
CVE-2007-4702 affects Apple Mac OS X 10.5 and Apple Mac OS X Server 10.5.
The primary risk of CVE-2007-4702 is that it allows unauthorized incoming connections to root processes, compromising system security.
Yes, CVE-2007-4702 can potentially be exploited remotely by attackers if certain conditions are met.