By John Gruber
Lex.Games: Free daily word games from Lex Friedman. Not the weird Elon stan;
the real Lex Friedman.
Leopard’s ARDagent — the background process that handles Apple Remote Desktop access — has a security hole, where it allows arbitrary AppleScripts to run as root, and, since AppleScript can execute shell scripts, arbitrary shell code to run as root too. Brian Krebs has uncovered proof-of-concept code that takes advantage of the hole.
★ Tuesday, 24 June 2008