CVE-2007-5829
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.
El escáner Disk Mount en Symantec AntiVirus para Macintosh versiones 9.x y 10.x, Norton AntiVirus para Macintosh versiones 10.0 y 10.1 y Norton Internet Security para Macintosh versiones 3.x , usa un directorio con permisos débiles (grupo grabable), que permite a usuarios administradores locales alcanzar privilegios de root mediante la sustitución de archivos no especificados, que se ejecutan cuando un usuario con acceso físico inserta un disco y la opción "Show Progress During Mount Scans" está habilitada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-11-05 CVE Reserved
- 2007-11-05 CVE Published
- 2024-06-24 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/40864 | Vdb Entry | |
http://securityresponse.symantec.com/avcenter/security/Content/2007.11.02.html | X_refsource_confirm | |
http://securitytracker.com/id?1018889 | Vdb Entry | |
http://securitytracker.com/id?1018890 | Vdb Entry | |
http://www.securityfocus.com/bid/26253 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38229 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27488 | 2017-07-29 | |
http://www.vupen.com/english/advisories/2007/3698 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 9.0 Search vendor "Symantec" for product "Norton Antivirus" and version "9.0" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 9.0.1 Search vendor "Symantec" for product "Norton Antivirus" and version "9.0.1" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 9.0.2 Search vendor "Symantec" for product "Norton Antivirus" and version "9.0.2" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 9.0.3 Search vendor "Symantec" for product "Norton Antivirus" and version "9.0.3" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 10.0 Search vendor "Symantec" for product "Norton Antivirus" and version "10.0" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 10.1 Search vendor "Symantec" for product "Norton Antivirus" and version "10.1" | macintosh |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Internet Security Search vendor "Symantec" for product "Norton Internet Security" | 3.0 Search vendor "Symantec" for product "Norton Internet Security" and version "3.0" | macintosh |
Affected
|