Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15771 | DTBF105 | SV-16710r2_rule | ECSC-1 | Medium |
Description |
---|
Although current version of Firefox have this set to disabled by default, use of this option can be harmful. This would allow the browser to access the Windows shell. This could allow access to the underlying system. This check verifies that the default setting has not been changed. |
STIG | Date |
---|---|
Mozilla FireFox STIG | 2011-05-21 |
Check Text ( C-16615r2_chk ) |
---|
Procedure: Open a browser window, type "about:config" in the address bar. Criteria: If the "network.protocol-handler.external.shell" value is "false", then this is not a finding. |
Fix Text (F-15988r2_fix) |
---|
Set the "network.protocol-handler.external.shell" value to "false" |