Apple released Remote Desktop 3.1 Update, Admin and Client
The 3.1 update is recommended for all users and addresses numerous issues related to overall reliability, usability and compatibility. It includes specific fixes for:
- remote lights out management of Xserve
- scanning computers on the local network
- installation of software meta-packages
- authentication when using directory services
- execution of AppleScript and Automator workflows
- compatibility with third party VNC viewers and servers
More details, including compatibility issues, are provided on this Apple Web page.
The security improvement is:
CVE-ID: CVE-2006-4413
Available for: Apple Remote Desktop 3.0
Impact: Malicious local users may be able to modify packages used to install or upgrade client systems
Description: Apple Remote Desktop includes built-in packages used to install and upgrade client systems. The permissions on these packages could allow them to be altered by malicious local users on Apple Remote Desktop admin systems. This could lead to the execution of arbitrary commands with root privileges on client systems when Apple Remote Desktop client software is installed or upgraded. This issue has been addressed by applying more restrictive permissions on the built-in installation packages. Credit to Andrew Mortensen of the University of Michigan for reporting this issue.
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?