ID

VAR-200701-0053


CVE

CVE-2007-0345


TITLE

Mac OS X of Activity Monitor.app/Contents/Resources/pmTool Etc. root Privileged vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2007-001405

DESCRIPTION

The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil. Mac OS X is prone to a local security vulnerability

Trust: 1.98

sources: NVD: CVE-2007-0345 // JVNDB: JVNDB-2007-001405 // BID: 86758 // VULHUB: VHN-23707

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.4.8

Trust: 2.4

vendor:applemodel:mac osscope:eqversion:x10.4.8

Trust: 0.3

sources: BID: 86758 // JVNDB: JVNDB-2007-001405 // CNNVD: CNNVD-200701-286 // NVD: CVE-2007-0345

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-0345
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-0345
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200701-286
value: MEDIUM

Trust: 0.6

VULHUB: VHN-23707
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-0345
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-23707
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-23707 // JVNDB: JVNDB-2007-001405 // CNNVD: CNNVD-200701-286 // NVD: CVE-2007-0345

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-0345

THREAT TYPE

local

Trust: 0.9

sources: BID: 86758 // CNNVD: CNNVD-200701-286

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200701-286

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-001405

PATCH

title:Top Pageurl:http://www.apple.com/macosx/

Trust: 0.8

sources: JVNDB: JVNDB-2007-001405

EXTERNAL IDS

db:NVDid:CVE-2007-0345

Trust: 2.8

db:EXPLOIT-DBid:3136

Trust: 2.0

db:OSVDBid:32700

Trust: 1.7

db:OSVDBid:32702

Trust: 1.7

db:OSVDBid:32701

Trust: 1.7

db:XFid:31530

Trust: 0.9

db:JVNDBid:JVNDB-2007-001405

Trust: 0.8

db:CNNVDid:CNNVD-200701-286

Trust: 0.7

db:MILW0RMid:3136

Trust: 0.6

db:BIDid:86758

Trust: 0.4

db:VULHUBid:VHN-23707

Trust: 0.1

sources: VULHUB: VHN-23707 // BID: 86758 // JVNDB: JVNDB-2007-001405 // CNNVD: CNNVD-200701-286 // NVD: CVE-2007-0345

REFERENCES

url:http://projects.info-pull.com/moab/moab-15-01-2007.html

Trust: 2.0

url:http://www.osvdb.org/32700

Trust: 1.7

url:http://www.osvdb.org/32701

Trust: 1.7

url:http://www.osvdb.org/32702

Trust: 1.7

url:https://www.exploit-db.com/exploits/3136

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/31530

Trust: 1.1

url:http://milw0rm.com/exploits/3136

Trust: 0.9

url:http://xforce.iss.net/xforce/xfdb/31530

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-0345

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-0345

Trust: 0.8

url:http://www.milw0rm.com/exploits/3136

Trust: 0.6

sources: VULHUB: VHN-23707 // BID: 86758 // JVNDB: JVNDB-2007-001405 // CNNVD: CNNVD-200701-286 // NVD: CVE-2007-0345

CREDITS

Unknown

Trust: 0.3

sources: BID: 86758

SOURCES

db:VULHUBid:VHN-23707
db:BIDid:86758
db:JVNDBid:JVNDB-2007-001405
db:CNNVDid:CNNVD-200701-286
db:NVDid:CVE-2007-0345

LAST UPDATE DATE

2025-04-10T23:05:46.277000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-23707date:2017-10-19T00:00:00
db:BIDid:86758date:2007-01-17T00:00:00
db:JVNDBid:JVNDB-2007-001405date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200701-286date:2007-01-21T00:00:00
db:NVDid:CVE-2007-0345date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-23707date:2007-01-18T00:00:00
db:BIDid:86758date:2007-01-17T00:00:00
db:JVNDBid:JVNDB-2007-001405date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200701-286date:2007-01-17T00:00:00
db:NVDid:CVE-2007-0345date:2007-01-18T02:28:00