Launching local programs through FileType handler

Window Snyder

8

Issue
We are currently investigating an issue on Windows XP, where some urls for “web” protocols that contain %00 launch the wrong handler and appear to be able to launch local programs, with limited argument passing.

Impact
The impact to users is unknown at this point in time. We are working to verify this and in the meantime, advise users to be cautious when browsing unknown sites.

Status
We are currently working on a fix. You can follow our work and process at: https://bugzilla.mozilla.org/show_bug.cgi?id=389580

Credit
Billy Rios and Nate McFeters posted details about this issue publicly at:http://xs-sniper.com/blog/remote-command-exec-firefox-2005/

8 responses

  1. Pingback from Techzi » Blog Archive » Mozilla flaw attack code published on ::

    […] security chief, Window Snyder, said that her team is working to verify and fix this latest […]

  2. Pingback from Mozilla flaw attack code published on ::

    […] security chief, Window Snyder, said that her team is working to verify and fix this latest […]

  3. Pingback from University Update - Firefox - Permanent Link to Launching local programs through FileType handler on ::

    […] Link to Article firefox Permanent Link to Launching local programs through FileType handler » […]

  4. Pingback from Mozilla’s Latest Firefox Security Issue » SELaplana on ::

    […] about the latest release of the Mozilla’s Firefox browsers and is now currently examined by Mozilla. We are currently investigating an issue on Windows XP, where some urls for “web” protocols […]

  5. Pingback from Dimension 2k : Blog Archive : Remote Command Execution Bug im Mozilla on ::

    […] Mozilla Security Blog]  Kategorien Software |  Security |  Internet  Tags bug, FireFox, […]

  6. Pingback from Security Tips » Firefox Fixes FileType Flaw on ::

    […] browsers. The very limited %00 argument needed to spur local program execution raised concerns at Mozilla, though the actual impact of such execution hadn’t been […]

  7. Pingback from Mozilla flaw attack code published « TechTitans™ on ::

    […] security chief, Window Snyder, said that her team is working to verify and fix this latest […]

  8. Pingback from » Protocol abuse adds to Firefox, Windows security woes | Ryan Naraine’s Zero Day | ZDNet.com on ::

    […] security chief Window Snyder has posted a confirmation of the latest issue: We are currently investigating an issue on Windows XP, where some urls for “web” protocols […]