Core Security released details on three iCal bugs last week. What’s suspicious is that Apple hasn’t fixed them yet, despite being told in January. The bugs are relatively harmless if you have iCal configured correctly – ie. to not automatically parse invitations from Mail. Unfortunately, that’s not the default on Leopard. I’ve run into the same problem before, and I turned the “feature” off for other reasons.

There’s a bug in the ics parser that could potentially allow for remote code execution. Not good.

Any program that automatically opens up attachments from your mail reader -Mail, Outlook, Thunderbird, etc. SHOULD BE RECONFIGURED! The same goes for remote images. Any attachment should be suspect unless you know who it came from, and SPAM does not qualify as “knowing who it came from”.

This simple configuration/re-configuration can save you a lot of headaches in the long run, in addition to any known vulnerabilities floating around, you’ve closed off a vector for new ones.

One thought on “Automatically opening attachments.

  1. Definitely agree with what you stated. Your explanation was actually the easiest to understand. I let you know, I normally get irked when people discuss points that they plainly have no idea about. You managed to hit the nail right on the head and defined out all the things without complication. Possibly, people can take a signal. Will seemingly be again to get more. Thanks

Comments are closed.