Security Update 2004-10-27 is now available and delivers the
following security enhancement for Apple Remote Desktop Client:
CVE-ID: CAN-2004-0962
Available for: Apple Remote Desktop Client v1.2.4 with Mac OS X
v10.3.x
Impact: An application can be started behind the loginwindow and it
will run as root
Description: For a system with the following pre-conditions:
* Apple Remote Desktop client installed
* A user on the client system has been enabled with the "Open and
quit applications" privilege
* The username and password of the ARD user is known
* Fast User Switching has been enabled
* A user is logged in, and loginwindow is active via Fast User
Switching
If the Apple Remote Desktop Administrator application on another
system is used to start a GUI application on the client, then the GUI
application will run as root behind the loginwindow. This update
prevents Apple Remote Desktop from launching applications when the
loginwindow is active.
This security enhancement is also present in Apple Remote Desktop
v2.1.
This issue does not affect systems prior to Mac OS X v10.3. Credit
to Andrew Nakhla and Secunia Research for reporting this issue.
Security Update 2004-10-27 may be obtained from the Software Update
pane in System Preferences, or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/
The download file is named: "SecurityUpdate2004-10-27.dmg"
Its SHA-1 digest is: 6f74180d4144affd3630e8824bff778ac39655e7