There was a lot of discussion about this yesterday on /.


'Tain't FOSS but it's often discussed here.  Just came across this little
>Root exploit for Mac OS X
>    A vulnerability in Mac OS X 10.4 and 10.5 makes it easy for potential 
>    attackers to obtain root rights to a system. The ARDAgent - Apple Remote 
>    Desktop - part of Remote Management has the SUID bit set. ARDAgent is
>    to run AppleScript with root rights and these, in turn, may contain
>    commands - all without requiring a password.
>    To demonstrate the problem as a standard user or guest on a computer,
>    osascript -e 'tell app "ARDAgent" to do shell script "whoami"'; into the 
>    console. Physical access to a system is not required for an attack to be 
>    successful. In principle, the exploit will also work remotely, say on a 
>    server on which a user has a restricted account with SSH access.
