Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2007-0752
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check..
CVSSv2.0 Score
- Severity
- High
- Base Score
- 7.2/10
- Exploit Score
- 3.9/10
- Access Vector
- Local
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 10/10
- Confidentiality Impact
- Complete
- Availability Impact
- Complete
- Integrity Impact
- Complete
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=537
- http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
- http://www.securityfocus.com/bid/24144
- http://www.osvdb.org/35144
- http://www.securitytracker.com/id?1018124
- http://secunia.com/advisories/25402
- http://www.vupen.com/english/advisories/2007/1939
- http://docs.info.apple.com/article.html?artnum=305530
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34503