Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-0230

Опубликовано: 02 мая 2005
Источник: debian
EPSS Низкий

Описание

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mozilla-firefoxnot-affectedpackage

Примечания

  • I don't know if this could work under Linux, anything I drag on the Desktop from firefox is convert to a Link

  • "when it has an image/gif content type but has a dangerous extension such as .bat or .exe, allows remote attackers

  • to ... execute arbitrary commands via malformed GIF files ... parsed by the Windows batch file parser

  • any interpretor would require the file to be +x to execute it and then would spit if handed a GIF

  • < vorlon> hacim: it's specific to Windows, home to the dumbest interpreter on the planet.

EPSS

Процентиль: 84%
0.0221
Низкий

Связанные уязвимости

ubuntu
около 20 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

nvd
около 20 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

github
около 3 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

EPSS

Процентиль: 84%
0.0221
Низкий