20.06.2008 13:50 Uhr, Quelle: Hardmac.com

Intego Announces a New Apple Remote Desktop Vulnerability

Intego reports to has identified a new vulnerability in Mac OS X 10.4 and 10.5 which is linked to the application Apple Remote Desktop. According to Intego, the ARD vulnerability would allow malicious programs to execute code as Root without requiring a password: A vulnerability has been discovered that allows malicious programs to execute code as root when run locally, or via a remote connection, on computers running Mac OS X 10.4 and 10.5. This vulnerability takes advantage of the fact that ARDAgent, a part of the Remote Management component of Mac OS X 10.4 and 10.5, has a setuid bit set. Any user running such an executable gains the privileges of the user who owns that executable. In this case, ARDAgent is owned by root, so running code via the ARDAgent executable runs this code as root, without requiring a password. The exploit in question depends on ARDAgent’s ability to run AppleScripts, which may, in turn, include sh

Weiterlesen bei Hardmac.com

Digg del.icio.us Facebook email MySpace Technorati Twitter

JustMac.info © Thomas Lohner - Impressum - Datenschutz