Intego, the maker of anti-malware software, sent us a note describing a vulnerability in Mac OS X 10.5 Leopard's "quarantine" system involving Mail attachments and providing a proof of concept. Intego rates the bug they term "OSX.Exploit.MetaData.B" as a low risk.
Intego's advice is the usual. Do not try to open attachments from people you do not know or that you do not expect even from people you know. This vulnerability was first posted by Heise Security. [Bill Fox]