CVE Vulnerabilities

CVE-2009-3376

Published: Oct 29, 2009 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.0-beta5 (including) 3.0-beta5 (including)
Firefox Mozilla 3.0.1 (including) 3.0.1 (including)
Firefox Mozilla 3.0.2 (including) 3.0.2 (including)
Firefox Mozilla 3.0.3 (including) 3.0.3 (including)
Firefox Mozilla 3.0.4 (including) 3.0.4 (including)
Firefox Mozilla 3.0.5 (including) 3.0.5 (including)
Firefox Mozilla 3.0.6 (including) 3.0.6 (including)
Firefox Mozilla 3.0.7 (including) 3.0.7 (including)
Firefox Mozilla 3.0.8 (including) 3.0.8 (including)
Firefox Mozilla 3.0.9 (including) 3.0.9 (including)
Firefox Mozilla 3.0.10 (including) 3.0.10 (including)
Firefox Mozilla 3.0.11 (including) 3.0.11 (including)
Firefox Mozilla 3.0.12 (including) 3.0.12 (including)
Firefox Mozilla 3.0.13 (including) 3.0.13 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)
Seamonkey Mozilla * 1.5.0.10 (including)
Seamonkey Mozilla 1.0 (including) 1.0 (including)
Seamonkey Mozilla 1.0-alpha (including) 1.0-alpha (including)
Seamonkey Mozilla 1.0-beta (including) 1.0-beta (including)
Seamonkey Mozilla 1.0.1 (including) 1.0.1 (including)
Seamonkey Mozilla 1.0.2 (including) 1.0.2 (including)
Seamonkey Mozilla 1.0.3 (including) 1.0.3 (including)
Seamonkey Mozilla 1.0.4 (including) 1.0.4 (including)
Seamonkey Mozilla 1.0.5 (including) 1.0.5 (including)
Seamonkey Mozilla 1.0.6 (including) 1.0.6 (including)
Seamonkey Mozilla 1.0.7 (including) 1.0.7 (including)
Seamonkey Mozilla 1.0.8 (including) 1.0.8 (including)
Seamonkey Mozilla 1.0.9 (including) 1.0.9 (including)
Seamonkey Mozilla 1.1 (including) 1.1 (including)
Seamonkey Mozilla 1.1-alpha (including) 1.1-alpha (including)
Seamonkey Mozilla 1.1-beta (including) 1.1-beta (including)
Seamonkey Mozilla 1.1.1 (including) 1.1.1 (including)
Seamonkey Mozilla 1.1.2 (including) 1.1.2 (including)
Seamonkey Mozilla 1.1.3 (including) 1.1.3 (including)
Seamonkey Mozilla 1.1.4 (including) 1.1.4 (including)
Seamonkey Mozilla 1.1.5 (including) 1.1.5 (including)
Seamonkey Mozilla 1.1.6 (including) 1.1.6 (including)
Seamonkey Mozilla 1.1.7 (including) 1.1.7 (including)
Seamonkey Mozilla 1.1.8 (including) 1.1.8 (including)
Seamonkey Mozilla 1.1.9 (including) 1.1.9 (including)
Seamonkey Mozilla 1.1.10 (including) 1.1.10 (including)
Seamonkey Mozilla 1.1.11 (including) 1.1.11 (including)
Seamonkey Mozilla 1.1.12 (including) 1.1.12 (including)
Seamonkey Mozilla 1.1.13 (including) 1.1.13 (including)
Seamonkey Mozilla 1.1.14 (including) 1.1.14 (including)
Seamonkey Mozilla 1.1.15 (including) 1.1.15 (including)
Seamonkey Mozilla 1.1.16 (including) 1.1.16 (including)
Seamonkey Mozilla 1.1.17 (including) 1.1.17 (including)
Seamonkey Mozilla 1.5.0.8 (including) 1.5.0.8 (including)
Seamonkey Mozilla 1.5.0.9 (including) 1.5.0.9 (including)
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.47.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.15-3.el4 *
Red Hat Enterprise Linux 4 RedHat nspr-0:4.7.6-1.el4_8 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-50.el4_8 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.12-25.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.15-3.el5_4 *
Red Hat Enterprise Linux 5 RedHat nspr-0:4.7.6-1.el5_4 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.15-3.el5_4 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:2.0.0.24-2.el5_4 *
Firefox-3.0 Ubuntu hardy *
Firefox-3.0 Ubuntu intrepid *
Firefox-3.0 Ubuntu jaunty *
Firefox-3.0 Ubuntu upstream *
Firefox-3.5 Ubuntu jaunty *
Firefox-3.5 Ubuntu karmic *
Firefox-3.5 Ubuntu upstream *
Thunderbird Ubuntu hardy *
Thunderbird Ubuntu intrepid *
Thunderbird Ubuntu jaunty *
Thunderbird Ubuntu karmic *
Thunderbird Ubuntu upstream *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9 Ubuntu upstream *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *
Xulrunner-1.9.1 Ubuntu upstream *

References