CVE-2007-5862: Critical severity Apple iOS and macOS vulnerability
Published Dec 18, 2007
·Updated
Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a crafted Java applet.
Affected Software
12 affected components
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.2
Remediation
Patch Available
Patch Available
Event History
Dec 18, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5862?
CVE-2007-5862 has been assigned a moderate severity rating due to the potential for unauthorized access to Keychain items.
2
How do I fix CVE-2007-5862?
To fix CVE-2007-5862, users should update their Mac OS X to the latest version that addresses this vulnerability.
3
What are the affected versions for CVE-2007-5862?
CVE-2007-5862 affects Mac OS X versions 10.4 through 10.4.11.
4
What type of vulnerability is CVE-2007-5862?
CVE-2007-5862 is a security vulnerability that allows remote code execution via a crafted Java applet.
5
Can CVE-2007-5862 be exploited locally?
CVE-2007-5862 is primarily an issue of remote exploitation, allowing attackers to add or delete Keychain items without local access.