The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x...
Vulnerability Description
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5829
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.02.html
- http://securitytracker.com/id?1018890
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38229
- http://secunia.com/advisories/27488
- http://www.securityfocus.com/bid/26253
- http://securitytracker.com/id?1018889
- http://www.vupen.com/english/advisories/2007/3698
- http://osvdb.org/40864
More from symantec
View All →Affected Vendor
symantec
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.