Leopard
The vulnerability lies in the way Mail handles image attachments

Mac Mail flaw resurfaces in Leopard

Flaw allows code to masquerade as images

Written by Shaun Nichols in California

Researchers have reported a vulnerability in Apple's Leopard operating system that the company had already patched.

Heise Security said in a news posting that it had found the flaw in Apple's Mail application.

The vulnerability lies in the way Mail handles image attachments. An attacker could take executable code and rename it as a .jpg file. Mail would then run the code without the user even being aware that an application had been started.

This could allow an attacker to distribute malicious code to users disguised as an image attachment.

Heise Security said that, while the unpatched vulnerability is unique to Apple's latest operating system, it is hardly new.

Apple patched the same flaw for Leopard's predecessor, MacOS 10.4 Tiger, in early 2006. When a user attempts to open the attachment in Tiger, a warning is displayed that the file is an executable and not an image.

"Apple apparently either did not incorporate this update into Leopard, or did not do it correctly," said Heise Security.

The security firm has set up a webpage which sends the user an email to test for the vulnerability.

Tags:

Further reading

Apple fixes Leopard firewall

New update addresses security issues   More...

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers   More...

Mac Trojan attack gathers steam

OS X attack being served up with PC malware   More...

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Related articles

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement