Mozilla Releases Firefox 2.0.0.7
Author: Dave Lewis

Mozilla has released Firefox 2.0.0.7 to address a security problem with QuickTime media-link files as described on pdp’s blog.
From Mozilla:
On his blog Petko D. Petkov reported that QuickTime Media-Link files contain a qtnext attribute that could be used on Windows systems to launch the default browser with arbitrary command-line options. When the default browser is Firefox 2.0.0.6 or earlier use of the -chrome option allowed a remote attacker to run script commands with the full privileges of the user. This could be used to install malware, steal local data, or otherwise corrupt the victim’s computer.
The fix for MFSA 2007-23 was intended to prevent this type of attack but QuickTime calls the browser in an unexpected way that bypasses that fix. To protect Firefox users from this problem we have now eliminated the ability to run arbitrary script from the command-line. Other command-line options remain, however, and QuickTime Media-link files could still be used to annoy users with popup windows and dialogs until this issue is fixed in QuickTime.
Tags: Firefix 2.0.0.7, Firefox Security Update, Firefox QuickTime Vulnerability




