[Forgot Password]
Login  Register Subscribe

24547

 
 

132804

 
 

129694

 
 

909

 
 

106691

 
 

152

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: UI selection timeout missing on download prompts - mfsa2014-03

ID: oval:org.secpod.oval:def:16699Date: (C)2014-02-10   (M)2018-12-13
Class: PATCHFamily: windows




Security researcher Jordi Chancel reported that the dialog for saving downloaded files did not implement a security timeout before button selections were processed. This could be used in concert with spoofing to convince users to select a different option than intended, causing downloaded files to be potentially opened instead of only saved in some circumstances.

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows 10
Product:
Mozilla SeaMonkey
Mozilla Firefox
Reference:
MFSA 2014-03
CVE-2014-1480
CVE    1
CVE-2014-1480
CPE    374
cpe:/a:mozilla:seamonkey:2.23:beta2
cpe:/a:mozilla:firefox:14.0
cpe:/a:mozilla:seamonkey:2.21:beta1
cpe:/a:mozilla:seamonkey:2.21:beta2
...

© SecPod Technologies