First published: Sat Nov 18 2006(Updated: )
Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Remote Desktop | <=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4413 is considered a high-severity vulnerability due to the potential for local users to gain root privileges.
To fix CVE-2006-4413, upgrade to Apple Remote Desktop version 3.1 or later.
CVE-2006-4413 affects systems running Apple Remote Desktop versions prior to 3.1.
Any local user on an Apple Remote Desktop administration system can exploit CVE-2006-4413.
The potential impacts of CVE-2006-4413 include unauthorized modification of packages and acquisition of root access on client systems.