Back

HIGH

Mozilla: Unescaped URIs passed to external programs

Published Aug 8, 2007

Description

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the versions of Firefox or Thunderbird as shipped with Red Hat Enterprise Linux.

Metrics

Weaknesses (1)

References (39)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 8, 2007
Updated Aug 7, 2024
Reserved Jul 18, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jul 30, 2008