Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3376

Опубликовано: 27 окт. 2009
Источник: redhat
CVSS2: 2.6

Описание

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=530168Firefox download filename spoofing with RTL override

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

nvd
почти 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

debian
почти 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

github
больше 3 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

oracle-oval
почти 16 лет назад

ELSA-2009-1530: firefox security update (CRITICAL)

2.6 Low

CVSS2