Toolkit
Story: IE may share Mozilla 'shell:' flaw
I seem to recall the vulnerability being not with Mozilla, but rather with the way that WindowsXP/2k itself handles the shell: protocol. Note that Microsoft was supposed to have already fixed this. But apparently they either only fixed it for Internet Explorer(a hack at best, since other browsers still suffer, like Opera. It probably falls under anti-trust activities also), or they didn't fix it at all. None of which surprises me. Microsoft doesn't care about whether or not the software is secure, they just want to make it look like it. Until Microsoft fixes the flaw at the operating system level, this flaw will remain in all browsers that allow the shell: protocol.
Full Talkback thread



