Computing.Net > Forums > Security and Virus > Firefox lances IE bug

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Firefox lances IE bug

Reply to Message Icon

Original Message
Name: IronMan
Date: July 19, 2007 at 05:13:41 Pacific
Subject: Firefox lances IE bug
OS: XP Pro
CPU/Ram: P4 / 512m
Model/Manufacturer: Data General
Comment:

Mozilla has pushed out a new version of Firefox that fixes a number of security bugs, including a high-profile bug involving launching Firefox from Internet Explorer.

Firefox version 2.0.0.5 also fixes a number of memory corruption and privilege escalation flaws, as explained in Mozilla's release notes.

FULL STORY


Report Offensive Message For Removal


Response Number 1
Name: XpUser
Date: July 19, 2007 at 06:37:19 Pacific
Reply: (edit)

Thanks for the head-up. IMO the simple workaround is don't launch FF from IE7 :-)

i_Xp/VistaUser


Report Offensive Follow Up For Removal

Response Number 2
Name: johnr
Date: July 19, 2007 at 09:54:00 Pacific
Reply: (edit)

Yes, I can see the advantage of launching IE from FF - incompatible pages etc. - but not the other way around.

"I've always been mad, I know I've been mad, like the most of us..."


Report Offensive Follow Up For Removal

Response Number 3
Name: IronMan
Date: July 19, 2007 at 22:50:55 Pacific
Reply: (edit)

XpUser and johnr, my original post in this thread is actually a follow-up to a post I made July 10 in the XP forum.

The launching of Firefox is due to a serious vulnerability that causes Internet Explorer to launch Firefox and execute a malicious payload; not a voluntary launch of Firefox by the user.

The vulnerability allows an attacker to remotely execute malicious code on a machine that is running IE but also has Firefox installed. By luring an IE user to a malevolently crafted site, the attacker can cause Firefox to execute the code without first vetting it for security.

Below is a link to the original story.

IronMan

LINK


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software