Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching a file handling program based on the file extension at the end of the URI, a variant of CVE-2007-4041. NOTE: the vendor states that it is still possible to launch a filetype handler based on extension rather than the registered protocol handler.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_xp | Microsoft | * | * |
Firefox | Ubuntu | dapper | * |
Firefox | Ubuntu | edgy | * |
Firefox | Ubuntu | feisty | * |
Iceape | Ubuntu | devel | * |
Midbrowser | Ubuntu | devel | * |
Mozilla-thunderbird | Ubuntu | dapper | * |
Mozilla-thunderbird | Ubuntu | edgy | * |
Mozilla-thunderbird | Ubuntu | feisty | * |