IE vs. Firefox vulnerability

Jul 11, 2007 12:21

When You Mix Firefox And IE, You Risk A Critical Zero-Day Flaw
Researchers have differing views of whether Microsoft or Mozilla is responsible for a zero-day that needs both browsers to be installed to cause a problem.

By Sharon Gaudin
InformationWeek
July 11, 2007 01:09 PM

[...]

What can happen is that if you visit a malicious website using IE, that website can make Mozilla Firefox start and then passes it a URL that is unchecked allowing it to run malicious javascript.

This same flaw cannot be played in reverse. That is, Firefox will not start an MSIE session and pass bad URLs.

Of course, Microsoft is claiming the upper hand and says the flaw is with Firefox.

Beware of using IE to surf the web. Bugs come in through open Windows.

security, microsoft

Previous post Next post
Up