Leopard Quarantine Bug Allows Launching of Malicious Attachments
TweetFollow Us on Twitter

Leopard Quarantine Bug Allows Launching of Malicious Attachments

Mac OS X Leopard Quarantine Bug Allows Users to Launch Malicious
Attachments in Mail

Exploit: OSX.Exploit.MetaData.B
Discovered: November 20, 2007
Risk: Low

http://www.intego.com/news/ism0706.asp

Description:

Mac OS X 10.5, Leopard, provides a "quarantine" system that alerts users
when they attempt to open applications that arrived via Mail, Safari or
iChat, or that came in disk images via these programs. It also alerts users
the first time they launch any other application they have installed or
manually added to their Applications folder. This system should inform
users of all cases when such executable files are being opened, but a bug
in the quarantine system, discovered by Heise Security on November 20,
2007, can allow users to launch attachments, which may be malicious, from
Mail.

The principle behind this system is Leopard's LaunchServices database,
which records all applications or executable files that are added to a
user's Mac. However, when some executable attachments arrive by e-mail,
this protection does not operate correctly. The current proof-of-concept
example is a shell script in a file with a .jpg extension. The file also
contains such information as a resource fork, telling which application
should open it (in this case, Terminal). The file also has appropriate
executable permissions.

Within Mail, this file shows as an attachment with a JPEG icon showing that
Preview will open it. But attempting to view the file with Quick Look shows
that it is not an image file.

A user receiving this file might be tempted to click it to see what it
contains. While this proof of concept merely displays some text in a
Terminal window, it would be simple to create a similar file with a single
command that, when executed in Terminal, would delete all of the user's
files.

When a user clicks on an attachment to an e-mail message in Mail, the
program stores a copy of the attachment in the user's Library/Mail
Downloads folder. This folder allows the Finder to then open the
attachment. When malicious attachments arrive in Mail containing a script
and a resource fork (its usro resource tells the Finder to open the file
with a specific application), a user can open these attachments once
without Mac OS X displaying the quarantine alert. When a user opens the
attachment at a later time, this alert displays, saying that the attachment
may be an application, and informing the user that it will be opened by
Terminal.

The bug causing this has to do with the way Leopard manages quarantines.
The first time a user opens an attachment, Mail opens the file directly
without passing through the quarantine system. Subsequent openings of the
same attachment cause Mail to no longer open the attachment directly, but
rather open the file it has saved in the Mail Downloads folder.

If a user receives a second message with the same attachment, the situation
is worse: they will receive no alert at all. Since the attachment has been
saved to the Mail Downloads folder, but from a different message, Mail does
not attempt to open the original attachment, but makes a copy of it (named:
(attachment name)-1, (attachment name)-2, etc.), and opens this attachment
with no warning.

Until this bug is corrected in Mac OS X 10.5, Mac users are at risk of
receiving maliciously crafted files, pretending to be image files, which
could delete all of a user's files, or may contain Trojan horses. It is
important that users do not open attachments from unknown senders,
especially those that come with spam messages.

Intego VirusBarrier X4 with its virus definitions dated November 21, 2007
protects against this problem. Since this bug allows maliciously crafted
files to execute with a single click from Mail, users are advised to check
for new virus definitions regularly, with NetUpdate, to make sure that they
are protected against any new exploits that may arrive.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All

Combo Quest (Games)
Combo Quest 1.0 Device: iOS Universal Category: Games Price: $.99, Version: 1.0 (iTunes) Description: Combo Quest is an epic, time tap role-playing adventure. In this unique masterpiece, you are a knight on a heroic quest to retrieve... | Read more »
Hero Emblems (Games)
Hero Emblems 1.0 Device: iOS Universal Category: Games Price: $2.99, Version: 1.0 (iTunes) Description: ** 25% OFF for a limited time to celebrate the release ** ** Note for iPhone 6 user: If it doesn't run fullscreen on your device... | Read more »
Puzzle Blitz (Games)
Puzzle Blitz 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: Puzzle Blitz is a frantic puzzle solving race against the clock! Solve as many puzzles as you can, before time runs out! You have... | Read more »
Sky Patrol (Games)
Sky Patrol 1.0.1 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0.1 (iTunes) Description: 'Strategic Twist On The Classic Shooter Genre' - Indie Game Mag... | Read more »
The Princess Bride - The Official Game...
The Princess Bride - The Official Game 1.1 Device: iOS Universal Category: Games Price: $3.99, Version: 1.1 (iTunes) Description: An epic game based on the beloved classic movie? Inconceivable! Play the world of The Princess Bride... | Read more »
Frozen Synapse (Games)
Frozen Synapse 1.0 Device: iOS iPhone Category: Games Price: $2.99, Version: 1.0 (iTunes) Description: Frozen Synapse is a multi-award-winning tactical game. (Full cross-play with desktop and tablet versions) 9/10 Edge 9/10 Eurogamer... | Read more »
Space Marshals (Games)
Space Marshals 1.0.1 Device: iOS Universal Category: Games Price: $4.99, Version: 1.0.1 (iTunes) Description: ### IMPORTANT ### Please note that iPhone 4 is not supported. Space Marshals is a Sci-fi Wild West adventure taking place... | Read more »
Battle Slimes (Games)
Battle Slimes 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: BATTLE SLIMES is a fun local multiplayer game. Control speedy & bouncy slime blobs as you compete with friends and family.... | Read more »
Spectrum - 3D Avenue (Games)
Spectrum - 3D Avenue 1.0 Device: iOS Universal Category: Games Price: $2.99, Version: 1.0 (iTunes) Description: "Spectrum is a pretty cool take on twitchy/reaction-based gameplay with enough complexity and style to stand out from the... | Read more »
Drop Wizard (Games)
Drop Wizard 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: Bring back the joy of arcade games! Drop Wizard is an action arcade game where you play as Teo, a wizard on a quest to save his... | Read more »

Price Scanner via MacPrices.net

Our MacBook Price Trackers will show you the...
Our Apple award-winning MacBook Price Trackers are continually updated with the latest information on prices, bundles, and availability for 16″ and 14″ MacBook Pros along with 13″ and 15″ MacBook... Read more
Amazon is offering a 10% discount on Apple’s...
Don’t pay full price! Amazon has 16-inch M4 Pro MacBook Pros (Silver and Black colors) on sale today for 10% off Apple’s MSRP. Shipping is free. These are the lowest prices currently available for 16... Read more
13-inch M4 MacBook Airs on sale for $150 off...
Amazon has new 13″ M4 MacBook Airs on sale for $150 off MSRP right now, starting at $849. Sale prices apply to most colors and configurations. Be sure to select Amazon as the seller, rather than a... Read more
15-inch M4 MacBook Airs on sale for $150 off...
Amazon has new 15″ M4 MacBook Airs on sale for $150 off Apple’s MSRP, starting at $1049. Be sure to select Amazon as the seller, rather than a third-party: – 15″ M4 MacBook Air (16GB/256GB): $1049, $... Read more
Amazon is offering a $50 discount on Apple’s...
Amazon has Apple’s 11th-generation A16 iPads in stock on sale for $50 (or a little more) off MSRP this week. Shipping is free: – 11″ 11th-generation 128GB WiFi iPads: $299 $50 off MSRP – 11″ 11th-... Read more
Clearance 13-inch M1 MacBook Airs available f...
Walmart has clearance, but new, Apple 13″ M1 MacBook Airs (8GB RAM, 256GB SSD) available online for $649, $360 off original MSRP, in Space Gray, Silver, and Gold colors. These are new MacBooks for... Read more
iPad minis on sale for $100 off Apple’s MSRP...
Amazon is offering $100 discounts (up to 20% off) on Apple’s newest 2024 WiFi iPad minis, each with free shipping. These are the lowest prices available for new minis among the Apple retailers we... Read more
AirPods Max headphones on sale for $479, $70...
Amazon has AirPods Max with USB-C on sale for $479.99 in all colors. Shipping is free. Their price is $70 off Apple’s MSRP, and it’s the lowest price available today for AirPods Max. Keep an eye on... Read more
14-inch M4 Pro/M4 Max MacBook Pros on sale th...
Don’t pay full price! Get a new 14″ MacBook Pro with an M4 Pro or M4 Max CPU for up to $320 off Apple’s MSRP this weekend at these retailers…they are the lowest prices available for these MacBook... Read more
Get a 15-inch M4 MacBook Air for $150 off App...
A couple of Apple retailers are offering $150 discounts on new 15″ M4 MacBook Airs this weekend. Prices at these retailers start at $1049: (1): Amazon has new 15″ M4 MacBook Airs on sale for $150 off... Read more

Jobs Board

All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.