PDA

View Full Version : Mozilla, Firefox, & Thunderbird Vulnerability



ShadowLab
07-09-2004, 12:30 PM
Just a heads up for all you Mozilla, Firefox, & Thunderbird users. A security issue has been confirmed for these products running on Windows systems only. Read the details and get the patch from: http://www.mozilla.org/security/shell.html

thevillageinn
07-10-2004, 01:15 AM
thanks for the info...

for anyone too lazy to click the link-

What Mozilla users should know about the shell: protocol security issue

On July 7 a security vulnerability affecting browsers for the Windows operating system was reported to mozilla.org by Keith McCanless, and was subsequently posted to Full Disclosure, a public security mailing list. On the same day, the Mozilla security team confirmed the report of this security issue affecting the Mozilla Application Suite, Firefox, and Thunderbird and discussed and developed the fix at Bugzilla bug 250180. We have confirmed that the bug affects only users of Microsoft's Windows operating system. The issue does not affect Linux or Macintosh users.

On July 8th, the Mozilla team released a configuration change which resolves this problem by explicitly disabling the use of the shell: external protocol handler. The fix is available in two forms. The first is a small download which will make this configuration adjustment for the user. The second fix is to install the newest full release of each of these products.

QuickGold
07-10-2004, 01:05 PM
Thanks for the link