SHARE
Facebook X Pinterest WhatsApp

Chicken? Or the Egg?

Written By
thumbnail
Web Webster
Web Webster
Jul 13, 2007

There’s this debate right now going on about a security hole in Firefox.

I haven’t linked to any of the coverage on Linux Today, because it seems to be a Windows-only issue. Interestingly, this exploit seems to also depend on Internet Explorer, and right now security analysts can’t seem to decide which browser is more at fault.

Here’s what’s happening.

If an IE user clicks on a firefoxurl: URI, the new page is launched in Firefox. According to Steve Kerrison over at Hexus:

Thor Larholm, discoverer of the flaw, writes: “it is possible to specify arbitrary arguments to the ‘firefox.exe’ process. This is where the ‘-chrome’ command line argument comes in handy, as it allows us to specify arbitrary Javascript code which is then executed within the privileges of trusted Chrome content…”

The debate comes in with these two sides of the argument: IE lets the fake request through, but Firefox still accepts it. Which, then, is more at fault?

Well, seeing how this fault isn’t showing up on Linux, or OS X for that matter, the fault clearly lies with…

Windows, perhaps the biggest exploit of them all.

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

DavMail 6.5 Exchange Gateway Brings Interactive Office 365 Login
Bobby Borisov
Nov 7, 2025
Bottles 51.25 Released With st Terminal Support
Bobby Borisov
Nov 7, 2025
Arch Linux Users Are the First to Experience KDE Plasma 6.5
Bobby Borisov
Nov 7, 2025
13 Useful Free and Open Source DNS Tools
webmaster
Nov 7, 2025
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.