Apple addresses file sharing security issue in Mac OS X 10.6.4
Security Update 2010-006 was issued Monday afternoon. It applies to Mac oS X 10.6.4 and Mac OS X Server. 10.6.4. The 1.93MB file is available through Software Update or direct from Apple.
The security update is recommended for all users of Snow Leopard, and it addresses an issue where a remote attacker could access shared folders on a system, as long as they knew the name of an account name on that system. By default, file sharing is not enabled on a Mac, meaning the issue would only affect those who have the service turned on.
The original problem was caused by an error handling issue in AFP Server within Mac OS X 10.6.4. The issue does not affect systems running a version of the operating system earlier than Snow Leopard.