First published: Thu Nov 15 2007(Updated: )
The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5 | |
Apple macOS Server | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4703 is considered a medium severity vulnerability due to the potential for unauthorized access by bypassing firewall restrictions.
To mitigate CVE-2007-4703, ensure that you upgrade to a later version of Mac OS X that addresses this vulnerability.
CVE-2007-4703 affects users of Apple Mac OS X 10.5 and Apple Mac OS X Server 10.5.
CVE-2007-4703 can be exploited by attackers using either remote connections or local root processes to bypass firewall settings.
A potential workaround for CVE-2007-4703 includes limiting the use of root processes or modifying firewall settings to enhance security.