MichaelP wrote: > Ben Bucksch wrote: > >> You haven't been infected, have you? If you care about attachments, >> you surely won't confirm the save. > > That's right - I have not been infected. But at the moment I opened > the message I felt helpless only being dependent on the capabilities > of may AV software.
You were /not/ "only being dependent on the capabilities of [your] AV software". Without AV software, you would just have to have clicked cancel. That being said, I agree that it is a very bad situation. We shouldn't show that dialog at all. It's Gecko stuff, though, so *I* can't fix it. > If the attachment is plain HTML, You are right. But what happens, if > not (like BadTrans &Co)? The same that happens when the bad HTML is in the body of the mail. Mozilla Mailnews is an HTML-capable mailer (after all, Netscape *invented* HTML-mail, IIRC, and still pushes it). If you don't like that fact (I'd agree with you), bug 30888 is one of the options for you.
