Mozilla Foundation Security Advisory 2005-10
javascript: links in Thunderbird launch Internet Explorer
- Announced
- January 21, 2005
- Reporter
- Tom Braun
- Impact
- Moderate to Critical
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 0.9
Description
Clicking on javascript: links in Thunderbird launched the default handler for that scheme registered with the OS. On the Windows operating system Internet Explorer is the default handler for the javascript: scheme even when Firefox is the default browser.
The risk associated with this depends on vulnerabilities in the installed version of Internet Explorer.
Workaround
Upgrade to the fixed version