Risk: Low
A vulnerability has been found in Mozilla Firefox that can permit system access if successfully exploited.
The issue arises because the '-chrome' parameter allows execution of arbitrary Javascript script code in chrome context. A malicious user can then exploit this to execute arbitrary commands on a user's system, for instance, using applications invoking Firefox with unfiltered command line arguments.
The flaw has been found in Firefox 1.x and 2.0.x; Firefox users are urged to download the latest update to fix this issue.