A new Firefox update fixes an unusual vulnerability that could cause malicious code to run if the browser is launched by Microsoft's Internet Explorer.
The critical vulnerability involves Internet Explorer's ability to launch other applications such as Excel or Firefox after a user clicks on a specially written link in a web page. Explorer does not properly check the syntax of the link, which could allow a malicious link to attack Firefox if launched, according to Mozilla, the open-source project that develops Firefox. Mozilla and Microsoft initially argued over who shoud fix it.
Microsoft said it didn't feel it was an issue for Explorer. Either way, Firefox's 184.108.40.206 release fixes the problem by now validating incoming data. The update will automatically be pushed out to Firefox 2.0 users via the built-in update system, Mozilla said in an advisory.
The update also fixes seven other vulnerabilities, two of which are considered ‘critical’ by Mozilla. One problem, labelled 2007-18, is a memory corruption problem that could cause arbitrary code to run on a machine. The other, 2007-21, could also allow arbitrary code to run.