http://community.cnr.com/thread/1015?tstart=0
Here is the quote from who I believe is the forum admin:
This continues to concern me. How come Ubuntu gets around the above issues without having to setuid? I still think this is poor security. This means that anyone on the system has the ability to install software as root through the CNR system. This makes my skin crawl.The setuid bit is turned on so that the CNR client runs as affectively root. This is done so that any user can install/unisntall/update software on a machine. We thought these activities are useful enough to warrant the use of setuid.
To quote the setuid folks, "In some cases these privileges are insufficient to do useful things, for example if the user had the ability to write to the /etc/passwd file they could alter or remove all users passwords - but without access to it they cannot change their own password!"
Oh, and I don't see plugin for firefox so I guess it uses the mime type stuff in Gnome or your desktop manager.

