Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
| Software | From | Fixed in |
|---|---|---|
| apple / apple_remote_desktop | 3.5.3 | 3.5.3.x |
| apple / apple_remote_desktop | 3.6.0 | 3.6.0.x |
| apple / apple_remote_desktop | 3.5.2 | 3.5.2.x |