Most Popular Articles
- MobileMe Mail and Gmail Go Down Simultaneously (11 Aug 2008)
- Comparing Apple's MobileMe Contrition with Google and Netflix (19 Aug 2008)
- iPhone Apps That Go Beyond Entertainment (08 Aug 2008)
- Jobs Personally Acknowledges iPhone Bug and Upcoming Fix (19 Aug 2008)
Recent TidBITS Talk Discussions
- Archiving a Time Capsule (3 messages)
- Google Chrome (20 messages)
- How to Protect Yourself From The New Mac OS X Trojans (29 messages)
- Cox.net Will Not Send from iPhone (57 messages)
Published in TidBITS 753. Subscribe today to receive TidBITS in email every Monday.
- Go Vote!
- Retrospect 6.0.204 Released
- Office X Updated Slightly
- DealBITS Drawing: DayLite Winners
- DealBITS Drawing: iMove from MaxUpgrades
- Apple Intros iPod Photo, iPod U2, and Euro iTMS
- Postini Brings Relief from Spam
- Hot Topics in TidBITS Talk/01-Nov-04
Security Update Patches Apple Remote Desktop
Security Update Patches Apple Remote Desktop -- Apple has released Security Update 2004-10-27, a patch to Apple Remote Desktop Client 1.2.4 that prevents a remote user from starting an application behind the login window, which would allow the application to run as root. The vulnerability exists on Mac OS X 10.3 systems with Apple Remote Desktop Client 1.2.4 installed and Fast User Switching enabled. On an unpatched system that has a user logged in, but the login window visible via Fast User Switching, an Apple Remote Desktop user with privileges to do so can start an application, which would run as root. (The vulnerability requires that the Remote Desktop user have a valid username and password to access the system; it does not expose the machine to unauthorized use.)
<http://docs.info.apple.com/article.html? artnum=61798>
The 832K download, available through Software Update or the Apple Downloads page, only applies to Mac OS X 10.3 and later operating systems, and isn't needed if Apple Remote Desktop has already been upgraded to version 2.1. [MHA]
<http://www.apple.com/support/downloads// securityupdate20041027ard.html>
MARK/SPACE, INC: Take it with you! The Missing Sync makesit easy to synchronize contacts, calendars, notes, photos
and more from your Mac to your BlackBerry, Palm OS, or
Windows Mobile phone. <http://www.markspace.com/bits>






