7.2
CVSSv2

CVE-2007-0753

Published: 24/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.3.3

apple mac os x 10.3.4

apple mac os x 10.4.1

apple mac os x 10.4.2

apple mac os x server 10.3

apple mac os x server 10.3.1

apple mac os x server 10.3.8

apple mac os x server 10.3.9

apple mac os x server 10.4.6

apple mac os x server 10.4.7

apple mac os x 10.3.1

apple mac os x 10.3.2

apple mac os x 10.3.9

apple mac os x 10.4

apple mac os x 10.4.8

apple mac os x 10.4.9

apple mac os x server 10.3.6

apple mac os x server 10.3.7

apple mac os x server 10.4.4

apple mac os x server 10.4.5

apple mac os x 10.3

apple mac os x 10.3.7

apple mac os x 10.3.8

apple mac os x 10.4.5

apple mac os x 10.4.6

apple mac os x 10.4.7

apple mac os x server 10.3.4

apple mac os x server 10.3.5

apple mac os x server 10.4.2

apple mac os x server 10.4.3

apple mac os x 10.3.5

apple mac os x 10.3.6

apple mac os x 10.4.3

apple mac os x 10.4.4

apple mac os x server 10.3.2

apple mac os x server 10.3.3

apple mac os x server 10.4

apple mac os x server 10.4.1

apple mac os x server 10.4.8

apple mac os x server 10.4.9

Exploits

source: wwwsecurityfocuscom/bid/24208/info Apple Mac OS X's VPN service daemon is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function Attackers may exploit this issue to crash the application or execute arbitrary code ...
# Copyright (c) 2007 Kevin Finisterre <kf_lists [at] digitalmunitioncom> # # CVE-ID: CVE-2007-0753 - docsinfoapplecom/articlehtml?artnum=305530 githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/4013targz (05302007-vpenistargz) # milw0rmcom [2007-05-30] ...