Red Hat Bugzilla – Bug 168737
CAN-2005-2968 Mozilla improper command line URL sanitization
Last modified: 2007-11-30 17:07:20 EST
The URL passed to mozilla on the command line does not properly escape dangerous
characters before handing the URL to the shell.
This issue should also affect RHEL2.1 and RHEL3
Note this is rated important not critical - a user would have to be tricked into
clicking on a link in an external application that contains the backtick characters.
After investigating the shell scripts Red Hat ships, we have determined that our
Mozilla pakcages are not vulnerable to this issue.