CVE-2007-4703 Information

Description

The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections even when \Block incoming connections\ has been set for its associated executable which might allow remote attackers or local root processes to bypass intended access restrictions.

Reference

http://docs.info.apple.com/article.html?artnum=307004 http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html http://secunia.com/advisories/27695 http://securitytracker.com/id?1018958 http://www.securityfocus.com/bid/26460 http://www.vupen.com/english/advisories/2007/3897 https://exchange.xforce.ibmcloud.com/vulnerabilities/38479

Share on: