Apple today released Security Update 2010-006 (Snow Leopard) which is recommended for all users and improves the security of Mac OS X.
Security Update 2010-006
• AFP
CVE-ID: CVE-2010-1820
Available for: Mac OS X v10.6.4, Mac OS X Server v10.6.4
Impact: A remote attacker may access AFP shared folders without a valid password
Description: An error handling issue exists in AFP Server. A remote attacker with knowledge of an account name on a target system may bypass the password validation and access AFP shared folders. By default, File Sharing is not enabled. This issue does not affect systems prior to Mac OS X v10.6. Credit to Richard Noll for reporting this issue.
Security Update 2010-006 (Snow Leopard) is available via Software Update and also as a standalone installer.
More info and download link (1.93MB) here.