It might not be a bad idea to proactively disarm this vulnerability on your own machine(s), as I just did:

sudo chmod -s System/Library/CoreServices/RemoteManagement/ ARDAgent.app/ARDAgent

That turns off the setuid bit. I'm sure that'll break Remote Desktop functionality, but that's still preferable to having your machine pwned. (And it can be fixed by using Disk Utility to repair permissions.)

—Jens

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________

Cocoa-dev mailing list (Cocoa-dev@lists.apple.com)

Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com

Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/cocoa-dev/archive%40mail-archive.com

This email sent to [EMAIL PROTECTED]

Reply via email to