CVE-2007-5829 (CNNVD-200711-054)
中文标题:
Symantec 多个产品 Disk Mount Scanner 本地特权提升漏洞
英文标题:
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macint...
漏洞描述
中文描述:
Macintosh 9.x和10.x版本下的Symantec AntiVirus , Macintosh 10.0和10.1版本下的Norton AntiVirus,以及Macintosh 3.x版本的Norton Internet Security中的Disk Mount scanner, 使用了一个弱许可权限的目录(全组写入权限),这使得本地admin权限用户可通过替换不确定的文件获得root权限,当具有物理访问权的用户插入一个磁盘并且"Show Progress During Mount Scans" 选项被激活时就会产生这一问题。
英文描述:
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| symantec | norton_antivirus | 9.0 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0:*:macintosh:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.1 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:macintosh:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.2 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:macintosh:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.3 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.3:*:macintosh:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0:*:macintosh:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1:*:macintosh:*:*:*:*:*
|
| symantec | norton_internet_security | 3.0 | - | - |
cpe:2.3:a:symantec:norton_internet_security:3.0:*:macintosh:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:L/AC:H/Au:S/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-5829 |
2025-11-11 15:17:56 | 2025-11-11 07:32:48 |
| NVD | nvd_CVE-2007-5829 |
2025-11-11 14:52:13 | 2025-11-11 07:41:34 |
| CNNVD | cnnvd_CNNVD-200711-054 |
2025-11-11 15:08:59 | 2025-11-11 07:49:21 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200711-054
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.0
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:H/Au:S/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']