what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mozilla Security Advisory 2004-07-07

Mozilla Security Advisory 2004-07-07
Posted Jul 8, 2004
Authored by Dan Veditz, Mozilla Foundation | Site mozilla.org

Mozilla Security Advisory - Windows versions of Mozilla products pass URIs using the shell: scheme to the OS for handling. The effects depend on the version of windows, but on Windows XP it is possible to launch executables in known locations or the default handlers for file extensions. It could be possible to combine this effect with a known buffer overrun in one of these programs to create a remote execution exploit, although at this time we have confirmed only denial-of-service type attacks. Versions affected: Mozilla (Suite), Mozilla Firefox, Mozilla Thunderbird.

tags | advisory, remote, overflow, shell
systems | windows
SHA-256 | 57a70625f36b6696077650b535747f47f76c4268befe5b019d687be4e6f7857d

Mozilla Security Advisory 2004-07-07

Change Mirror Download
Mozilla Security Advisory
July 7, 2004

Summary: Windows shell: scheme exposed in Mozilla
Products: Mozilla (Suite)
Mozilla Firefox
Mozilla Thunderbird
Fixed in: Mozilla (Suite) 1.7.1
Mozilla Firefox 0.9.2
Mozilla Thunderbird 0.7.2


Description:
Windows versions of Mozilla products pass URIs using the shell: scheme
to the OS for handling. The effects depend on the version of windows,
but on Windows XP it is possible to launch executables in known
locations or the default handlers for file extensions. It could be
possible to combine this effect with a known buffer overrun in one
of these programs to create a remote execution exploit, although
at this time we have confirmed only denial-of-service type attacks
(including crashing the system in some cases).

Solution:
We urge people to install the patch available on mozilla.org or
install the latest version of the software.

http://www.mozilla.org/security/shell.html

-Dan Veditz
Mozilla Security Group
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close