CVE-2005-1576

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
References
Link Resource
http://secunia.com/secunia_research/2004-11/advisory/ Exploit Patch Vendor Advisory
http://www.osvdb.org/16432 Exploit Vendor Advisory
http://secunia.com/advisories/12979 Exploit Patch Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*

Information

Published : 2005-05-11 21:00

Updated : 2008-09-05 13:49


NVD link : CVE-2005-1576

Mitre link : CVE-2005-1576


JSON object : View

Advertisement

dedicated server usa

Products Affected

mozilla

  • firefox