CVE-2020-6797
published 2020-03-02CVE-2020-6797: By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is…
PriorityP421medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.48%
71.2th percentile
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 73.0 | 73.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 73 | 73 |
| mozilla | firefox | >= unspecified < ESR68.5 | ESR68.5 |
| mozilla | firefox_esr | < 68.5.0 | 68.5.0 |
| mozilla | thunderbird | < 68.5.0 | 68.5.0 |
| mozilla | thunderbird | >= unspecified < 68.5 | 68.5 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
vendor_redhat·2020-02-11·CVSS 4.3
CVE-2020-6797 [MEDIUM] CWE-250 Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6)
Debian
CVE-2020-6797: firefox - By downloading a file with the .fileloc extension, a semi-privileged extension c...
vendor_debian·2020·CVSS 4.3
CVE-2020-6797 [MEDIUM] CVE-2020-6797: firefox - By downloading a file with the .fileloc extension, a semi-privileged extension c...
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-07: CVE-2020-6797
vendor_mozilla·CVSS 4.3
CVE-2020-6797 [MEDIUM] Mozilla Foundation Security Advisory 2020-07: CVE-2020-6797
Mozilla Foundation Security Advisory 2020-07
CVE: CVE-2020-6797
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 68.5
Mozilla
Mozilla Foundation Security Advisory 2020-06: CVE-2020-6797
vendor_mozilla·CVSS 4.3
CVE-2020-6797 [MEDIUM] Mozilla Foundation Security Advisory 2020-06: CVE-2020-6797
Mozilla Foundation Security Advisory 2020-06
CVE: CVE-2020-6797
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.5
Mozilla
Mozilla Foundation Security Advisory 2020-05: CVE-2020-6797
vendor_mozilla·CVSS 4.3
CVE-2020-6797 [MEDIUM] Mozilla Foundation Security Advisory 2020-05: CVE-2020-6797
Mozilla Foundation Security Advisory 2020-05
CVE: CVE-2020-6797
Product: Firefox
Impact: high
Fixed in: Firefox 73
GHSA
GHSA-x22j-8886-rjmh: By downloading a file with the
ghsa_unreviewed·2022-05-24
CVE-2020-6797 [MEDIUM] CWE-20 GHSA-x22j-8886-rjmh: By downloading a file with the
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
No detection rules found.
No public exploits indexed.
Bugzilla
Browser API can lead to 'one click' Remote Code Execution
bugzilla·2021-10-02
Browser API can lead to 'one click' Remote Code Execution
Browser API can lead to 'one click' Remote Code Execution
Created attachment 9244062
inetloc.zip
[VULNERABILITY DETAILS]
macOS has vulnerability due to insufficient input validation by the Finder (com.apple.generic-internet-location)
An attacker could exploit this vulnerability by providing crafted inetloc file.
This vulnerability bypasses Apple's File Quarantine and Gatekeeper technologies, and allows arbitrary code execution.
By the way, Using Firefox Extension API (browser.downloads.download / browser.downloads.open) can lead to 'one-click' Remote Code Execution via .inetloc file.
[VERSION]
Firefox Version: 92.0.1 (64bit)
Operating System: macOS Big Sur, version 11.5.1(20G80)
[REPRODUCTION CASE]
1. Install the attacked extension
2. Just click cute cat image in the popup
3. "bin
HackerOne
Uncovering file quarantine and UX security issues in macOS apps ( .terminal, .fileloc and .url)
hackerone·2021-07-23
Uncovering file quarantine and UX security issues in macOS apps ( .terminal, .fileloc and .url)
Uncovering file quarantine and UX security issues in macOS apps ( .terminal, .fileloc and .url)
Slides : https://docs.google.com/presentation/d/19WeQbqc_OKnrSv1I3Z4sm-oNAf6IVzHwRyQP4i9Bv_Y/edit#slide=id.g758ad3e042_23_231
See Blogpost for more details - https://medium.com/@metnew/exploiting-popular-macos-apps-with-a-single-terminal-file-f6c2efdfedaa
# Summary
Popular macOS apps with a file-sharing functionality didn't delegate file quarantine to OS leading to File Quarantine bypass (Windows MOTW analogue) for downloaded files. The vulnerability has low/moderate impact, but it can be combined with other custom behaviours, and UX features to increase the severity.
During the research, I also discovered two "insecure features" in macOS: dangerous handling of .fileloc and .url shortcut file
Bugzilla
CVE-2020-6797 Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
bugzilla·2020-02-11·CVSS 4.3
CVE-2020-6797 [MEDIUM] CVE-2020-6797 Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
CVE-2020-6797 Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact.
*Note: this issue only occurs on Mac OSX. Other operating systems are unaffected.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-06/#CVE-2020-6797
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Vladimir Metnew
https://bugzilla.mozilla.org/show_bug.cgi?id=1596668https://security.gentoo.org/glsa/202003-02https://www.mozilla.org/security/advisories/mfsa2020-05/https://www.mozilla.org/security/advisories/mfsa2020-06/https://www.mozilla.org/security/advisories/mfsa2020-07/https://bugzilla.mozilla.org/show_bug.cgi?id=1596668https://security.gentoo.org/glsa/202003-02https://www.mozilla.org/security/advisories/mfsa2020-05/https://www.mozilla.org/security/advisories/mfsa2020-06/https://www.mozilla.org/security/advisories/mfsa2020-07/
2020-03-02
Published