Firefox & IE Together Brew Up Security Trouble

Posted on July 11th, 2007 by Jason

That’s the latest update from security researchers who initially laid the blame on Microsoft’s Explorer for the latest zero-day exploit that also can afflict those using the browser. Users could face a “highly critical” risk if they have both IE and version 2.0, or later, loaded on their computer.

The trouble begins when browsing a malicious site while using IE and it registers a “firefoxurl://” URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the . As a result, users may find their systems remotely compromised. Earlier Tuesday, security researcher Thor Larholm, who discovered the IE flaw, and security research giant put much of the blame on IE, while Secunia’s Thomas Kristensen, chief technology officer, attributed the problem to versions 2.0 or later.

“It’s a little bit of both,” said Oliver Friedrichs, director of ’s Security Response Center. “You have two very complex applications that are not playing well together and leading to a security issue. The components themselves are secure as stand-alone products but not together.” “ is the current attack vector, but Explorer is to blame for not escaping…characters when passing on the input to the command line,” said Larholm, in response to a reader’s comments.

“I agree that could have registered its URL handler with pure DDE (dynamic data exchange, the protocol for information exchange) instead and thereby have avoided the possibility of a command-line argument injection, but IE should still be able to safely launch external applications.” Friedrichs noted that while , which released version 2 in October, has gained in popularity, most users will also have IE loaded on their computers, since it comes with the Windows operating system.

Tags: , , , , , , , ,

Share and Enjoy:
  • del.icio.us
  • StumbleUpon
  • Facebook
  • Google
  • Furl
  • Live
  • MisterWong.DE
  • NewsVine
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb
  • BlinkList
  • description
  • Fark
  • Netvouz
  • Spurl
  • MisterWong
  • Webnews.de
  • Blogsvine
  • description
  • IndiaGram
  • kick.ie
  • Taggly
  • E-mail this story to a friend!
  • Print this article!

Related posts

3 Responses to “Firefox & IE Together Brew Up Security Trouble”

  1. deepu865 on 11 Jul 2007 at 1:23 pm #

    10x its very nice

  2. Techno World on 12 Jul 2007 at 6:55 pm #

    The trouble begins when browsing a malicious site while using IE and it registers a “firefoxurl://” URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the Webmore…

  3. StumbleUpon » Your page is now on StumbleUpon! on 04 Aug 2007 at 8:47 am #

    [...] Your page is on StumbleUpon [...]

Leave a Reply