Jump to content


- - - - -

Firefox and IE together brew up security trouble


  • Please log in to reply
2 replies to this topic

#1 Nvyseal

Nvyseal

    Chairman of the Board

  • Administrator
  • PipPipPipPipPipPip
  • 9,830 posts
  • Location:From the whatever it is, Pluto
  • Country:USA

Posted 10 July 2007 - 08:34 PM

images/news/firefox.jpgA user could face a "highly critical" risk if they have both IE and Firefox version 2.0, or later, loaded on their computer. The trouble begins when browsing a malicious site while using IE and it registers a "firefoxurl://" URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the Web. A user, as a result, may find his or her system remotely compromised.

"Firefox is the current attack vector but Internet Explorer is to blame for not escaping ... characters when passing on the input to the command line," said Larholm, in response to a reader's comments. "I agree that Firefox could have registered its URL handler with pure DDE (dynamic data exchange, the protocol for information exchange) instead and thereby have avoided the possibility of a command-line argument injection, but IE should still be able to safely launch external applications."

Read more @ C/Net


#2 VROSA

VROSA

    Ghost Member

  • Global Moderator
  • PipPipPipPipPip
  • 2,043 posts
  • Location:Belo Horizonte - Minas Gerais - Brazil
  • Interests:Hardware, Software, Alphas and Betas, OS Mods, Windows 8.1, Windows 10, Linux, Games, Fun, Friends.
  • Country:Brazil

Posted 11 July 2007 - 02:55 PM

It is a quite complex flaw... i hope there is a fix soon.

#3 Tweak

Tweak

    Established Member

  • Members
  • PipPipPipPipPip
  • 674 posts
  • Country:US

Posted 14 July 2007 - 01:45 AM

The fix is simple, remove firefox and use Opera...hehe.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users