9.3
CVSSv2

CVE-2007-4687

Published: 15/11/2007 Updated: 29/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The remote_cmds component in Apple Mac OS X 10.4 up to and including 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4.7

apple mac os x 10.4.8

apple mac os x server 10.4.5

apple mac os x server 10.4.6

apple mac os x 10.4.2

apple mac os x 10.4.3

apple mac os x 10.4.4

apple mac os x server 10.4.10

apple mac os x server 10.4.2

apple mac os x server 10.4.9

apple mac os x 10.4.5

apple mac os x 10.4.6

apple mac os x server 10.4.3

apple mac os x server 10.4.4

apple mac os x 10.4.1

apple mac os x 10.4.10

apple mac os x 10.4.9

apple mac os x server 10.4.1

apple mac os x server 10.4.7

apple mac os x server 10.4.8