MEDIUM · 5.4

CVE-2007-0734

fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password p...

Vulnerability Description

fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption.

CVSS Score

5.4

MEDIUM

AV:A/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AppleAirport Extreme<= 7.0
AppleMac Os X10.3.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-0734?

CVE-2007-0734 is a vulnerability with a CVSS score of 5.4 (MEDIUM). fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password p...

How severe is CVE-2007-0734?

CVE-2007-0734 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0734?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Airport Extreme, Apple Mac Os X.