[link] Firefox 0.9.2 / Thunderbird 0.7.2

FireFox 0.9.2 | Thunderbird 0.7.2

From Internet Storm Center

Mozilla and Firefox Update Fixes Vulnerability

It's time to update your browser, though this time the problem is not with Internet Explorer, but with Mozilla and Firefox running on Windows. As described in the eWeek article at http://www.eweek.com/article2/0,1759,1621463,00.asp, a flaw in the way Mozilla and Firefox handled links containing the shell: suffix could allow a malicious web site to run arbitrary code on the visitor's system. We advise you to upgrade to Mozilla 1.7.1 or Firefox 0.9.2 to patch this vulnerability. Alternatively, you may install the patch from http://ftp.mozilla.org/pub/mozilla.org/moz.../shellblock.xpi.

For more information about this vulnerability and ways of addressing it, please see http://mozilla.org/security/shell.html. This URL also points out that Thunderbird, an email client that's part of the Mozilla suite, is vulnerable, and explains how you can address the Thunderbird vulnerability as well.

Also, with the release of Thunderbird 0.7.2, Thunderbird is no longer vulnerable, as that article suggests.

#188859