[Forgot Password]
Login  Register Subscribe

25354

 
 

132805

 
 

137672

 
 

909

 
 

112213

 
 

156

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: UI selection timeout missing on download prompts - mfsa2014-03

ID: oval:org.secpod.oval:def:16699Date: (C)2014-02-10   (M)2020-01-14
Class: PATCHFamily: windows




Security researcher Jordi Chancel reported that the dialog for saving downloaded files did not implement a security timeout before button selections were processed. This could be used in concert with spoofing to convince users to select a different option than intended, causing downloaded files to be potentially opened instead of only saved in some circumstances.

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows 10
Product:
Mozilla SeaMonkey
Mozilla Firefox
Reference:
MFSA 2014-03
CVE-2014-1480
CVE    1
CVE-2014-1480
CPE    374
cpe:/a:mozilla:seamonkey:2.21:beta1
cpe:/a:mozilla:seamonkey:2.21:beta2
cpe:/a:mozilla:seamonkey:2.19:beta2
cpe:/a:mozilla:seamonkey:2.19:beta1
...

© SecPod Technologies