CVE-2005-0230Mozilla Firefox vulnerability

3 documents3 sources
Severity
5.1MEDIUMNVD
EPSS
2.2%
top 15.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-f235-r39g-2m8r: Firefox 12022-05-01

📋Vendor Advisories

1
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28