Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability



Date Discovered

July 10, 2007


Microsoft Internet Explorer, Mozilla Firefox and Netscape Navigator are prone to a vulnerability that lets attackers inject commands through the 'firefoxurl' and 'navigatorurl' protocol handlers. Exploiting these issues allows remote attackers to pass and execute arbitrary commands and arguments through the 'firefox.exe' and 'navigator.exe' processes by employing the 'firefoxurl' and 'navigatorurl' handlers. An attacker can also employ these issues to carry out cross-browser scripting attacks by using the '-chrome' argument. This can allow the attacker to run JavaScript code with the privileges of trusted Chrome context and gain full access to Firefox and Netscape Navigator's resources. Exploiting these issues would permit remote attackers to influence command options that can be called through the 'firefoxurl' and 'navigatorurl' handlers and therefore execute commands and script code with the privileges of a user running the applications. Successful attacks may result in a variety of consequences, including remote unauthorized access.

Technologies Affected

  • Google Chrome
  • Google Chrome
  • Google Chrome
  • Google Chrome
  • Google Chrome
  • HP HP-UX B.11.11
  • HP HP-UX B.11.23
  • HP HP-UX B.11.31
  • Mandriva Corporate Server 3.0.0 X86 64
  • Mandriva Corporate Server 3.0.0
  • Mandriva Corporate Server 4.0
  • Mandriva Corporate Server 4.0.0 X86 64
  • Mandriva Linux Mandrake 2007.0
  • Mandriva Linux Mandrake 2007.0 X86 64
  • Mandriva Linux Mandrake 2007.1
  • Mandriva Linux Mandrake 2007.1 X86 64
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1
  • Microsoft Internet Explorer 7.0
  • Microsoft Internet Explorer 7.0 Beta1
  • Microsoft Internet Explorer 7.0 Beta2
  • Microsoft Internet Explorer 7.0 Beta3
  • Mozilla Camino 0.7.0 .0
  • Mozilla Camino 0.8.0
  • Mozilla Camino 0.8.3
  • Mozilla Camino 0.8.4
  • Mozilla Camino 1.0
  • Mozilla Camino 1.0.1
  • Mozilla Camino 1.0.2
  • Mozilla Camino 1.0.3
  • Mozilla Camino 1.5
  • Mozilla Firefox 2.0
  • Mozilla Firefox 2.0 Beta 1
  • Mozilla Firefox 2.0 RC2
  • Mozilla Firefox 2.0 RC3
  • Mozilla Firefox
  • Mozilla Firefox
  • Mozilla Firefox
  • Mozilla Firefox
  • Mozilla SeaMonkey 1.1 Beta
  • Mozilla SeaMonkey 1.1.1
  • Mozilla SeaMonkey 1.1.2
  • Mozilla SeaMonkey 1.1.3
  • Mozilla Thunderbird 1.5.0
  • Mozilla Thunderbird 1.5.0 Beta 2
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Mozilla Thunderbird
  • Netscape Navigator 9.0
  • Slackware Linux 11.0
  • Slackware Linux 12.0
  • SuSE Linux 10.0 Ppc
  • SuSE Linux 10.0 X86
  • SuSE Linux 10.0 X86-64
  • SuSE Linux 10.1 Ppc
  • SuSE Linux 10.1 X86
  • SuSE Linux 10.1 X86-64
  • SuSE Linux Desktop 10
  • SuSE Linux Personal 10.0.0 OSS
  • SuSE Linux Personal 10.1
  • SuSE Linux Professional 10.0.0 OSS
  • SuSE Linux Professional 10.0.0
  • SuSE Linux Professional 10.1
  • SuSE Novell Linux Desktop 9.0.0
  • SuSE Novell Linux POS 9
  • SuSE Open-Enterprise-Server
  • SuSE SUSE LINUX Retail Solution 8.0.0
  • SuSE SUSE Linux Enterprise Server 10
  • SuSE SUSE Linux Enterprise Server 10 SP1
  • SuSE SUSE Linux Enterprise Server 8
  • SuSE SuSE Linux Openexchange Server 4.0.0
  • SuSE SuSE Linux School Server for i386
  • SuSE Suse Linux Enterprise Desktop 10
  • SuSE Suse Linux Enterprise Desktop 10 SP1
  • SuSE Suse Linux Standard Server 8.0.0
  • SuSE UnitedLinux 1.0.0
  • SuSE openSUSE 10.2
  • Ubuntu Ubuntu Linux 6.06 LTS Amd64
  • Ubuntu Ubuntu Linux 6.06 LTS I386
  • Ubuntu Ubuntu Linux 6.06 LTS Powerpc
  • Ubuntu Ubuntu Linux 6.06 LTS Sparc
  • Ubuntu Ubuntu Linux 6.10 Amd64
  • Ubuntu Ubuntu Linux 6.10 I386
  • Ubuntu Ubuntu Linux 6.10 Powerpc
  • Ubuntu Ubuntu Linux 6.10 Sparc
  • Ubuntu Ubuntu Linux 7.04 Amd64
  • Ubuntu Ubuntu Linux 7.04 I386
  • Ubuntu Ubuntu Linux 7.04 Powerpc
  • Ubuntu Ubuntu Linux 7.04 Sparc


Do not follow links provided by unknown or untrusted sources.
To reduce the likelihood of successful exploits, never visit sites of questionable integrity or follow links provided by unfamiliar or untrusted sources.

Do not accept communications that originate from unknown or untrusted sources.
Users should never open or accept unsolicited HTML email, because it may provide an attack vector for numerous vulnerabilities. Filter all HTML email or disable client support for HTML email.

Run all software as a nonprivileged user with minimal access rights.
To limit the impact of client vulnerabilities, perform all nonadministrative tasks, such as reading email and browsing, as an unprivileged user with minimal access rights.

Mozilla has addressed this vulnerability in Firefox and Thunderbird. The vendor has released Firefox and Thunderbird to fix this issue. Please see the references for more information. NOTE: Microsoft has released a report on this issue, stating that it is not the responsibility of the calling application to encode or otherwise escape characters passed to protocol handlers. Please see the referenced MSDN article for more information. NOTE: This issue was not correctly fixed Thunderbird installed through automatic updates. The vendor released Thunderbird to resolve this issue. Please see the referenced Mozilla advisories for more information.



Thor Larholm reported this issue for Internet Explorer. Greg Macanus reported this issue for Mozilla Firefox. Nathan McFeters discovered that 'navigatorurl' is also affected. Billy Rios is also credited with the discovery of this issue.

© 1995- Symantec Corporation

Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Security Response. Reprinting the whole or part of this alert in any medium other than electronically requires permission from


The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.

Symantec, Symantec products, Symantec Security Response, and are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.