Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Apple > Apple & Mac Blog

September 18th, 2012, 07:07 GMT · By

BLOG

Apple Patches “Information Disclosure” Bug in Remote Desktop Software

SHARE:

Adjust text size:


Remote Desktop marketing material Enlarge picture - Remote Desktop marketing material
Apple has patched a security flaw in its Remote Desktop software noting that connections to a third-party VNC server with the "Encrypt all network data" setting on may lead to information disclosure.

A stub over at Apple’s security section on support.apple.com notes that Apple Remote Desktop 3.5.3 addresses a security issue. Although the update also brings some other changes and improvements, security seems to be the key reason why Apple rolled out this new version.

The Cupertino mammoth explains that, “When connecting to a third-party VNC server with ‘Encrypt all network data’ set, data is not encrypted and no warning is produced.” In other words, this could lead to information disclosure.

By creating an SSH tunnel for the VNC connection in this configuration, and preventing the connection, Apple was able to patch this issue with the help of one Mark S. C. Smith studying at Central Connecticut State University, who reported the problem.

Apple points out that this issue doesn’t affect Apple Remote Desktop 3.5.1 and earlier versions.

TELL US WHAT YOU THINK:

1,017 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Download Apple Remote Desktop 3.5.3 Admin

2012 iPod shuffle Has New Texture and Pop

iPhone 5: Camera and Photo/Video Capabilities

iPhone 5: How Powerful the A6 Chip Really Is

Apple Confirms More Stores Where You Can Get an iPhone 5 This Friday

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM