X

Apple releases Security Update 2004-10-27

Apple releases Security Update 2004-10-27

CNET staff

Apple has posted Security Update 2004-10-27, available through Software Update or as a standalone download.

The update addresses a potential vulnerability in Apple Remote Desktop Client 1.2.4 with Mac OS X 10.3.x where an application can be started behind the loginwindow and it will run as root. The vulnerability exists for a systems with the following conditions:

  • Apple Remote Desktop client installed
  • A user on the client system has been enabled with the Open and quit applications privilege
  • The username and password of the ARD user is known
  • Fast user switching has been enabled
  • A user is logged in, and loginwindow is active via Fast User Switching

Knowledge Base article #61798 states "If the Apple Remote Desktop Administrator application on another system is used to start a GUI application on the client, then the GUI application would run as root behind the loginwindow. This update prevents Apple Remote Desktop from launching applications when the loginwindow is active. This security enhancement is also present in Apple Remote Desktop v2.1. This issue does not affect systems prior to Mac OS X 10.3. Credit to Andrew Nakhla and Secunia Research for reporting this issue."

Problems with the new release? Let us know.

Resources

  • #61798
  • Let us know
  • More from Late-Breakers