Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."
References
Link Providers
http://bugzilla.mozilla.org/show_bug.cgi?id=389580 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579 cve-icon cve-icon
http://secunia.com/advisories/26234 cve-icon cve-icon
http://secunia.com/advisories/26258 cve-icon cve-icon
http://secunia.com/advisories/26303 cve-icon cve-icon
http://secunia.com/advisories/26309 cve-icon cve-icon
http://secunia.com/advisories/26331 cve-icon cve-icon
http://secunia.com/advisories/26335 cve-icon cve-icon
http://secunia.com/advisories/26393 cve-icon cve-icon
http://secunia.com/advisories/26572 cve-icon cve-icon
http://secunia.com/advisories/27326 cve-icon cve-icon
http://secunia.com/advisories/27414 cve-icon cve-icon
http://secunia.com/advisories/28135 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.010101 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1344 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1345 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1346 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1391 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:152 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2007:047 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:047 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-27.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/475265/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/475450/30/5550/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25053 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-493-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-503-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4256 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0082 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=389106 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1600 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3845 cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3845 cve-icon
https://www.mozilla.org/en-US/security/advisories/mfsa2007-27/ cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-08-08T01:11:00

Updated: 2024-08-07T14:28:52.500Z

Reserved: 2007-07-18T00:00:00

Link: CVE-2007-3845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-08-08T01:17:00.000

Modified: 2023-11-07T02:00:55.070

Link: CVE-2007-3845

cve-icon Redhat

Severity : Critical

Publid Date: 2008-07-30T00:00:00Z

Links: CVE-2007-3845 - Bugzilla