Multiple web browsers contain a flaw that may allow a remote attacker to launch a program from a known location. The issue is triggered when rendering specially-crafted web page using the "shell:" command. This requires the attacker to trick a user into visiting the web page.
Classification
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to Mozilla 1.7.1 or higher, Firefox 0.9.2, Thunderbird 0.7.2, Netscape 7.2, K-Meleon 0.9 or higher as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the patch provided in the external references.