[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-0230Date: (C)2005-05-02   (M)2024-03-27


Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-12468
SECUNIA-19823
http://marc.info/?l=bugtraq&m=110780995232064&w=2
GLSA-200503-10
GLSA-200503-30
SUSE-SA:2006:004
http://www.mikx.de/firedragging/
http://www.mozilla.org/security/announce/mfsa2005-25.html
https://bugzilla.mozilla.org/show_bug.cgi?id=279945
oval:org.mitre.oval:def:100033

CPE    1
cpe:/a:mozilla:firefox:1.0
OVAL    1
oval:org.mitre.oval:def:100033

© SecPod Technologies