Release date:
Updated on:
Affected Systems:
Apple Remote Desktop 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55100
Cve id: CVE-2012-0681
Apple Remote Desktop is the best way to manage Mac computers on your network.
When connecting to a third-party VNC Server and setting "Encrypt all network data" in Apple Remote Desktop 3.5.2-3.6, data is transmitted in unencrypted mode without warning, remote attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Mark S. C. Smith
Link: http://secunia.com/advisories/50352/
Http://support.apple.com/kb/HT5433
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (HT5433) and corresponding patches for this:
HT5433: About the security content of Apple Remote Desktop 3.6.1
Link: http://support.apple.com/kb/HT5433