newscritical flaw found in firefox 2 0 0 4
News

Critical flaw found in Firefox 2.0.0.4

Security research firm Secunia has uncovered a security flaw in the latest version of Firefox (2.0.0.4) that it labels “highly critical.” The flaw can reportedly be exploited by malicious users in order to compromise a victim’s machine. Secunia describes the flaw as follows:

The problem is that Firefox registers the “firefoxurl://” URI handler and allows invoking firefox with arbitrary command line arguments. Using e.g. the “-chrome” parameter it is possible to execute arbitrary Javascript in chrome context. This can be exploited to execute arbitrary commands e.g. when a user visits a malicious web site using Microsoft Internet Explorer.

Secunia says it confirmed the vulnerability’s presence in Firefox 2.0.0.4 on Windows XP Service Pack 2, and that “other versions may also be affected.” Aside from simply avoiding malicious websites, Secunia CTO Thomas Kristensen tells CNet that system administrators can get around the hole by un-registering or removing the Firefox URI handler. Neither Kristensen nor CNet provides instructions for that procedure, however.

Cyril Kowaliski

Latest News

deelance 5
Blog, Crypto News, News

DeeLance Price Prediction – This Web 3.0 Decentralized Freelancer Project’s Presale Will Explode!

crypto
Blog, Crypto News

The 6 Best Cryptos To Buy On Presale This Week!

The crypto market is a trading ground for thousands of coins ready to deliver excellent use cases and gains to their investors. Despite the past year’s bearish storm, the market...

ecoterra presale
Blog, Crypto News, News

5 reasons Brand New Green Crypto, Ecoterra Will Explode on Presale!

Pollution has reached critical levels, and it is more than obvious that something must be done. However, it is not enough to tell people they must do something because that...

As you move your SMB profitability to the next level, project management software can help meet your specific needs. Here's a quick overview.
Software News

How to Choose Project Management Software for a Small Business

Tor’s Lookalike Loots $400k in Crypto
News

Tor’s Lookalike Loots $400k in Crypto

Microsoft Starts Running Ads in Its New AI-Powered Bing Chat
Blog

Microsoft Starts Running Ads in Its New AI-Powered Bing Chat

TamaDoge Run
Blog, Crypto News, Gaming News, News

Tamadoge Release Details of 5th Arcade Game – Tama Run!