CVE Vulnerabilities

CVE-2009-3376

Published: Oct 29, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.0-beta5 (including)3.0-beta5 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
FirefoxMozilla3.0.6 (including)3.0.6 (including)
FirefoxMozilla3.0.7 (including)3.0.7 (including)
FirefoxMozilla3.0.8 (including)3.0.8 (including)
FirefoxMozilla3.0.9 (including)3.0.9 (including)
FirefoxMozilla3.0.10 (including)3.0.10 (including)
FirefoxMozilla3.0.11 (including)3.0.11 (including)
FirefoxMozilla3.0.12 (including)3.0.12 (including)
FirefoxMozilla3.0.13 (including)3.0.13 (including)
FirefoxMozilla3.5.1 (including)3.5.1 (including)
FirefoxMozilla3.5.2 (including)3.5.2 (including)
FirefoxMozilla3.5.3 (including)3.5.3 (including)
SeamonkeyMozilla*1.5.0.10 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-alpha (including)1.0-alpha (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.4 (including)1.0.4 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.4 (including)1.1.4 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
SeamonkeyMozilla1.1.13 (including)1.1.13 (including)
SeamonkeyMozilla1.1.14 (including)1.1.14 (including)
SeamonkeyMozilla1.1.15 (including)1.1.15 (including)
SeamonkeyMozilla1.1.16 (including)1.1.16 (including)
SeamonkeyMozilla1.1.17 (including)1.1.17 (including)
SeamonkeyMozilla1.5.0.8 (including)1.5.0.8 (including)
SeamonkeyMozilla1.5.0.9 (including)1.5.0.9 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.47.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.15-3.el4*
Red Hat Enterprise Linux 4RedHatnspr-0:4.7.6-1.el4_8*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-50.el4_8*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-25.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.15-3.el5_4*
Red Hat Enterprise Linux 5RedHatnspr-0:4.7.6-1.el5_4*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.15-3.el5_4*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.24-2.el5_4*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
Firefox-3.5Ubuntujaunty*
Firefox-3.5Ubuntukarmic*
Firefox-3.5Ubuntuupstream*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*

References