Leopard Mail May Include Tiger Security Flaw
Leopard Mail May Include Tiger Security Flaw
by , 9:40 AM EST, November 21st, 2007
Heise Security says Apple's Mail application in Mac OS X 10.5 may include a security flaw that the company previously patched in Mac OS X 10.4. The flaw could allow an attacker to trick Mail users into running an application by disguising it as a JPEG email attachment.
Apple patched the flaw in Tiger's Mail application in March 2006, but somehow it seems the same security hole was reintroduced when Leopard shipped at the end of October.
The security company has developed a demonstration showing the flaw. The demonstration emails a harmless attachment that launches the Terminal application and displays the contents of the current directory.
This potential security flaw appears to impact Leopard users only. Tiger users with current updates installed are not impacted.
Observer Comments
I use Gmail - GMail (Google) filters virii (viruses) and any other malware from my incoming email. There is spam reporting/moving feature as well. And GMail works well on Safari!
So this does not bother me.
But I would like to point out that this will bother those who use the Mail app exclusively. How much of a bother is up to the user. From a bit to a lot...
In that case, I am concerned about the luckless users.
Guest, now celebrating his 1,234th post...
Wed Nov 21, 2007 8:09 pm Subject: Didn't work for me
I did their demo and it didn't do what they said it would... so I don't know about their vulnerability. (I did look at the code on a different machine before executing the potential virus.. it was as they say, a simple and harmless shell script.) It will be interesting to see what others say about this.
This totally worked for me. You go to their web site and enter your email address and they mail you. Clicking once on the ".jpg" attachment brings up the Terminal and runs a script, which does an 'ls' and prints a message basically saying you are owned.
The second time I clicked on the ".jpg", it didn't work and the correct warning dialog came up. It turns out it only works once each time Mail is started.
The script doesn't get root or admin privileges if you are running as a normal user. But if it contained "rm -rf ~/*" you would basically be screwed. It could also modify your ~/Library to get a bot to run in the background when you are logged in, I think. Apple absolutely has to fix this, despite what any fanboys say.
This isn't a flaw in Mail and everyone knows it. It's a flaw in the way the system chooses icons for display. The system is smart enough (?) to read the RSRC to run the trojan but not smart enough to get the icon from there? How come other third party utilities are smart enough? It's not Mail it's the entire Apple system and Apple never fixed this but hey - you hold your breath JG and they'll fix it right soon now.
Comments are currently closed. Please email the author instead.
Recent Headlines - Updated July 9th
- Thu, 4:29 PM
- News - SEC Investigating Jobs Health Disclosures
- 3:50 PM
- Ted Landau's User Friendly Blog - User Interface Blues
- 3:42 PM
- Reports - Chrome OS Complicates Apple & Google Boards of Directors
- 1:08 PM
- Deal Brothers - Life ‘09 Software Drops to $59.99 Delivered
- 11:06 AM
- News - TechRestore Posts Stop-motion iPhone 3GS Breakdown
- 10:17 AM
- Hot Forum Topic - Parallels versus Fusion: Reader Favorites
- 9:32 AM
- Product News - LaCie Unveils LaCinema Rugged HD Multimedia Hard Drive
- 8:54 AM
- Product News - CheckUp 2.5 Adds Snow Leopard, New Mac Support
- 8:37 AM
- News - Latest Microsoft Ad Hits at MacBook Price Again
- 8:06 AM
- TMO Appearances - TMO’s Jeff Gamet Dives into Social Media at CoMUG
- 7:30 AM
- The Back Page - Looking Ahead at the App Store’s Future
- Wed, 6:48 PM
- Games - Pipe Mania Puzzle Game Released for Mac, iPhone
The Mac Observer Reader Specials
- Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
OWC: Big Drives, High Performance - Not High Prices! SATA 3.5" up to 1.5TB. Notebook up to 500GB. FW up to 6.0TB. 1.0TB Drive Models from as low as $97.99 www.MacSales.com
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!
RamJet Memory: MacBook and MacBook Pro 4GB kits for $57.99! Mac Pro 4GB Kits $99.99! iMac and Mac mini 4GB Kits for $57.99! 1TB SATA Hard Drives for $109.99! Click hereFor the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

