As far as I know, all Windows versions prior to 0.9.2 are affected, but they don't specifically say. Non-Windows systems are unaffected; this is more a problem with Windows's security model (or lack thereof) than a Firefox bug. You can grab this to fix the problem (when using Firefox; other URL-interpreting programs probably have the same hole) instead of reinstalling; both ways simply make Firefox reject shell: URLs.
Sure enough, it's been sighted in Word and MSN Messenger. Microsoft's response was predictable, and can be summed up by their most famous declaration to the same effect: "That vulnerability is completely theoretical."
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.