Lovers^Park

The Last 10 Topics

  1. MP3 Blogs
  2. p3k says OPPS
  3. Highlights of the Climbing Session on 04th July (S...
  4. Repent! The end is near!
  5. Cosplay 2k1
  6. FUCK YOU P3k
  7. Suckiest Story of the Week (by the way Delon, FUCK...
  8. IE? Seriously, I'm not too sure why I still use WI...
  9. Yes..i support the IE-free movement ! Go Firefox ...
  10. What p3k Learns From the News

PSA: Patch Your Firefox

by Jeiel Aranal @ Friday, July 09, 2004

It's come to my attention, through Slashdot, that there's a vulnerability on Windows based Mozilla products that allows arbitrary code to be run. More info, as well as the patch, can be found on this Newsforge page.

From the page:

The kicker is that this isn't even a problem with Mozilla; it's a problem with Windows Explorer. Windows XP Service Pack 1 was supposed to have closed this hole, but apparently it is still functioning and leaving Windows systems open to remote attack. So the Mozilla team worked to patch a hole that had little to do with their project.

Is this really a security hole? When Mozilla receives a shell: request, it passes it on to an external handler in Windows. The "fix" for this is to disable this functionality which, as far as I can tell, is totally unnecessary to begin with. External handlers -- programs outside Mozilla -- have no specific security model, so the only way to deal with them is to make individual exceptions like this one. Messy? Yes. But that's Windows.

-Jeiel Aranal

0 Comments

Post a Comment