There’s a hole in Mozilla and Firefox! However…
Seems there’s a potential hole in Windows NT/2000/XP renditions of Mozilla (1.7.0 and earlier), Firefox (0.9.1 and earlier), and Thunderbird (0.7.1 and earlier), which could allow an attacker to open other software on the Windows system or even crash it.
I know that R* is formulating a lengthy respose to me about how that just proves that IE is better - or at least he will formulate one when he gets around to reading this post. However, NewsForge has already defeated his arguments. (neener.)
It’s also worth noting that the vulnerability (the shell: URI) is in Windows itself; Mozilla products on every other OS are unaffected. It’s also worth noting that a patch was issued the same day the hole was reported, that there are still no reports to BugTraq that the patch broke anything, and that affected users can choose to either get a new version of their software or just install the patch from here.
Those of you who haven’t yet discovered a real Web browser may wish to read mozilla.org’s “Switching from Internet Explorer to Mozilla Firefox“, which walks through installation and initial configuration. It’s quite simple, and tabbed browsing is usually enough by itself to make ex-IE-heads wonder why they didn’t get on the Mozilla train earlier.
Tags: Geeky, unsolicited advice










