Saturday, July 10, 2004

Mozilla Flaw Lets Links Run Arbitrary Programs

Mozilla Flaw Lets Links Run Arbitrary Programs:
"The Mozilla Foundation has confirmed findings that its Mozilla and Firefox browsers are vulnerable to attacks using the 'shell:' scheme, which execute arbitrary code under Windows without the user having to click a link."

Security researchers are reporting another security issue in Web browsing under Windows, but this time Internet Explorer is not the culprit. The Mozilla Foundation's Mozilla and Firefox are reported as vulnerable.

The Mozilla Foundation has confirmed the problem and issued a fix, which is available here.

http://update.mozilla.org/extensions/moreinfo.php?id=154

http://www.eweek.com/article2/0,1759,1621451,00.asp?kc=ewnws070904dtx1k0300599

No comments: