CVE Vulnerabilities

CVE-2009-3376

Published: Oct 29, 2009 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Affected Software

Name Vendor Start Version End Version
Seamonkey Mozilla 1.1.10 1.1.10
Seamonkey Mozilla 1.0.3 1.0.3
Firefox Mozilla 3.5.3 3.5.3
Seamonkey Mozilla 1.1.8 1.1.8
Firefox Mozilla 3.0.7 3.0.7
Seamonkey Mozilla 1.0.1 1.0.1
Seamonkey Mozilla 1.1.7 1.1.7
Firefox Mozilla 3.0.9 3.0.9
Seamonkey Mozilla 1.0.6 1.0.6
Seamonkey Mozilla 1.0.9 1.0.9
Seamonkey Mozilla 1.1.3 1.1.3
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 3.0.8 3.0.8
Seamonkey Mozilla 1.1.17 1.1.17
Seamonkey Mozilla 1.1.5 1.1.5
Seamonkey Mozilla 1.0.7 1.0.7
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 3.0.4 3.0.4
Seamonkey Mozilla 1.1 1.1
Firefox Mozilla 3.0.5 3.0.5
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.1.12 1.1.12
Firefox Mozilla 3.5.1 3.5.1
Seamonkey Mozilla 1.1 1.1
Firefox Mozilla 3.5.2 3.5.2
Seamonkey Mozilla 1.1.14 1.1.14
Seamonkey Mozilla 1.1.2 1.1.2
Firefox Mozilla 3.0.10 3.0.10
Seamonkey Mozilla 1.0.2 1.0.2
Seamonkey Mozilla 1.0.8 1.0.8
Seamonkey Mozilla * 1.5.0.10
Seamonkey Mozilla 1.1.11 1.1.11
Firefox Mozilla 3.0.12 3.0.12
Seamonkey Mozilla 1.5.0.9 1.5.0.9
Firefox Mozilla 3.0.3 3.0.3
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1.1 1.1.1
Seamonkey Mozilla 1.5.0.8 1.5.0.8
Seamonkey Mozilla 1.0.5 1.0.5
Seamonkey Mozilla 1.1.15 1.1.15
Firefox Mozilla 3.0.6 3.0.6
Seamonkey Mozilla 1.1.6 1.1.6
Seamonkey Mozilla 1.1.16 1.1.16
Firefox Mozilla 3.0.1 3.0.1
Firefox Mozilla 3.0.2 3.0.2
Seamonkey Mozilla 1.0.4 1.0.4
Seamonkey Mozilla 1.1.9 1.1.9
Seamonkey Mozilla 1.1.13 1.1.13
Firefox Mozilla 3.0 3.0
Firefox Mozilla 3.0.13 3.0.13
Seamonkey Mozilla 1.1.4 1.1.4
Firefox Mozilla 3.0.11 3.0.11

References