CVE-2007-5829
Last modified
CVE-2007-5829 is a vulnerability of currently unknown severity. The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Norton Antivirus | 9.0 |
| Symantec | Norton Antivirus | 9.0.1 |
| Symantec | Norton Antivirus | 9.0.2 |
| Symantec | Norton Antivirus | 9.0.3 |
| Symantec | Norton Antivirus | 10.0 |
| Symantec | Norton Antivirus | 10.1 |
| Symantec | Norton Internet Security | 3.0 |
References
- http://secunia.com/advisories/27488Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3698Vendor Advisory
- http://secunia.com/advisories/27488Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3698Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5829?
How severe is CVE-2007-5829?
How do I fix CVE-2007-5829?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5823Directory traversal vulnerability in forum.php in Ben Ng Scr…
- CVE-2007-5824webserver.c in mt-dappd in Firefly Media Server 0.2.4 and ea…
- CVE-2007-5825Format string vulnerability in the ws_addarg function in web…
- CVE-2007-5826Absolute path traversal vulnerability in the EDraw Flowchart…
- CVE-2007-5827iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permi…
- CVE-2007-5828Cross-site request forgery (CSRF) vulnerability in the admin…
- CVE-2007-5830Unspecified vulnerability in the administrative interface in…
- CVE-2007-5831Directory traversal vulnerability in fileSystem.do in SSL-Ex…
- CVE-2007-5832Unspecified vulnerability in selectLanguage.do in SSL-Explor…
- CVE-2007-5833Multiple cross-site scripting (XSS) vulnerabilities in BosDe…
- CVE-2007-5834Cross-site scripting (XSS) vulnerability in BosDev BosNews 4…
- CVE-2007-5835Install.php in BosDev BosNews 4 and 5 does not require authe…
Are you affected by CVE-2007-5829?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
