Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > macOS > Security Update 2004-10-27 in Software update

Security Update 2004-10-27 in Software update
Thread Tools
Mr. Blur
Professional Poster
Join Date: Aug 2001
Location: Somewhere, but not here.
Status: Offline
Reply With Quote
Oct 27, 2004, 04:45 PM
 
...thread title says it all.
Artificial intelligence is no match for natural stupidity...
     
piracy
Mac Elite
Join Date: Mar 2001
Status: Offline
Reply With Quote
Oct 27, 2004, 04:48 PM
 
http://www.apple.com/support/downloa...041027ard.html
http://docs.info.apple.com/article.html?artnum=61798

Security Update 2004-10-27
Apple Remote Desktop

Available for: Apple Remote Desktop Client 1.2.4 with Mac OS X 10.3.x
CVE-ID: CAN-2004-0962
Impact: An application can be started behind the loginwindow and it will run as root.
Description: For a system with these following conditions
Apple Remote Desktop client installed
A user on the client system has been enabled with the Open and quit applications privilege
The username and password of the ARD user is known
Fast user switching has been enabled
A user is logged in, and loginwindow is active via Fast User Switching
If the Apple Remote Desktop Administrator application on another system is used to start a GUI application on the client, then the GUI application would run as root behind the loginwindow. This update prevents Apple Remote Desktop from launching applications when the loginwindow is active. This security enhancement is also present in Apple Remote Desktop v2.1. This issue does not affect systems prior to Mac OS X 10.3. Credit to Andrew Nakhla and Secunia Research for reporting this issue.
     
Person Man
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
Oct 27, 2004, 04:48 PM
 
Um, details?
     
piracy
Mac Elite
Join Date: Mar 2001
Status: Offline
Reply With Quote
Oct 27, 2004, 04:48 PM
 
Originally posted by Person Man:
Um, details?
     
Person Man
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
Oct 27, 2004, 04:49 PM
 
Originally posted by piracy:


I was hoping it would fix the /Library/StartupItems permissions oversight.
     
Person Man
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
Oct 27, 2004, 07:03 PM
 
Oh, by the way. This update does NOT require a restart.
     
ManOfSteal
Addicted to MacNN
Join Date: Aug 2004
Location: Outfield - #24
Status: Offline
Reply With Quote
Oct 27, 2004, 08:14 PM
 
Originally posted by Person Man:
Oh, by the way. This update does NOT require a restart.
Phew...

My uptime was approaching 22 hours...I would HATE to start over!
     
johnt519
Forum Regular
Join Date: Apr 2003
Status: Offline
Reply With Quote
Oct 27, 2004, 08:24 PM
 
Hrm. Not showing up in SU for me (yet anyway).

I'll keep checking.
     
Person Man
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
Oct 27, 2004, 09:15 PM
 
Originally posted by johnt519:
Hrm. Not showing up in SU for me (yet anyway).

I'll keep checking.
Do you have Apple Remote Desktop 2.1 installed? That software already has the update in it, so it would not be needed in that case.
     
VValdo
Dedicated MacNNer
Join Date: May 2001
Status: Offline
Reply With Quote
Oct 27, 2004, 09:18 PM
 
Well I don't have the Apple Remote Desktop installed (I use VNC)...

...so why did I need this update? According to the description, ARD is required for this to be a vulnerability...

W
     
Person Man
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
Oct 28, 2004, 01:00 AM
 
Originally posted by VValdo:
Well I don't have the Apple Remote Desktop installed (I use VNC)...

...so why did I need this update? According to the description, ARD is required for this to be a vulnerability...

W
Panther has the Remote Desktop Client (version 1.x) built in.
     
johnt519
Forum Regular
Join Date: Apr 2003
Status: Offline
Reply With Quote
Oct 28, 2004, 01:23 AM
 
Nope, don't have remote desktop. And it's still not listed as available on two of my systems. iTunes/Quicktime took until today to finally show up in SU.

Guess I'm just at the bottom of the update list.
     
Boondoggle
Grizzled Veteran
Join Date: May 1999
Location: Seattle
Status: Offline
Reply With Quote
Oct 28, 2004, 09:24 AM
 
I'm not seeing it either on my PB, but my iMac found it...
1.25GHz PowerBook


i vostri seni sono spettacolari
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 06:08 PM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,