CVE-2007-3744Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple MAC OS X

Severity
5.8MEDIUMNVD
EPSS
6.6%
top 8.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 1

Description

Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.

CVSS vector

AV:A/AC:L/C:P/I:P/A:PExploitability: 6.5 | Impact: 6.4

Affected Packages2 packages

NVDapple/mac_os_x11 versions+10
NVDapple/mac_os_x_server11 versions+10

Patches

🔴Vulnerability Details

1
GHSA
GHSA-c4f5-524q-wgpg: Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac2022-05-01
CVE-2007-3744 — Apple MAC OS X vulnerability | cvebase