CVE-2007-5829
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
05/11/2007
Last modified:
09/04/2025
Description
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physical access inserts a disk and the "Show Progress During Mount Scans" option is enabled.
Impact
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:symantec:norton_antivirus:9.0:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:9.0.3:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:10.0:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_antivirus:10.1:*:macintosh:*:*:*:*:* | ||
| cpe:2.3:a:symantec:norton_internet_security:3.0:*:macintosh:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/40864
- http://secunia.com/advisories/27488
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.02.html
- http://securitytracker.com/id?1018889=
- http://securitytracker.com/id?1018890=
- http://www.securityfocus.com/bid/26253
- http://www.vupen.com/english/advisories/2007/3698
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38229
- http://osvdb.org/40864
- http://secunia.com/advisories/27488
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.02.html
- http://securitytracker.com/id?1018889=
- http://securitytracker.com/id?1018890=
- http://www.securityfocus.com/bid/26253
- http://www.vupen.com/english/advisories/2007/3698
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38229



