Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Security update for shell: extenal protocol vulnerability

1 view
Skip to first unread message

Asa Dotzler

unread,
Jul 9, 2004, 12:43:52 AM7/9/04
to
Today, the Mozilla team released a configuration change which fixes the
shell: external protocol vulnerability by explicitly disabling the use
of the shell: external protocol handler. The fix is available in a small
patch or in the newest full release of each of these products.

The XPI patch for all of Mozilla, Firefox and Thunderbird is available
at
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/shellblock.xpi

New Windows builds of Mozilla, Firefox, and Thunderbird are available at:
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/mozilla-win32-1.7.1-installer.exe
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.9.2/FirefoxSetup-0.9.2.exe
http://ftp.mozilla.org/pub/mozilla.org/thunderbird/releases/0.7.2/ThunderbirdSetup-0.7.2.exe

More information and detailed instructions about updating your Mozilla
applications can be found at http://mozilla.org/security/shell.html

--Asa

0 new messages