Leopard
The vulnerability lies in the way Mail handles image attachments

Mac Mail flaw resurfaces in Leopard

Flaw allows code to masquerade as images

Written by Shaun Nichols in California

Researchers have reported a vulnerability in Apple's Leopard operating system that the company had already patched.

Heise Security said in a news posting that it had found the flaw in Apple's Mail application.

The vulnerability lies in the way Mail handles image attachments. An attacker could take executable code and rename it as a .jpg file. Mail would then run the code without the user even being aware that an application had been started.

This could allow an attacker to distribute malicious code to users disguised as an image attachment.

Heise Security said that, while the unpatched vulnerability is unique to Apple's latest operating system, it is hardly new.

Apple patched the same flaw for Leopard's predecessor, MacOS 10.4 Tiger, in early 2006. When a user attempts to open the attachment in Tiger, a warning is displayed that the file is an executable and not an image.

"Apple apparently either did not incorporate this update into Leopard, or did not do it correctly," said Heise Security.

The security firm has set up a webpage which sends the user an email to test for the vulnerability.

Tags:

Further reading

Apple fixes Leopard firewall

New update addresses security issues   More...

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers   More...

Mac Trojan attack gathers steam

OS X attack being served up with PC malware   More...

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Related articles

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement