CVE-2005-0230

Firefox 1.0 - Arbitrary Command Execution via Malformed GIF File Dragging

Title source: llm
STIX 2.1

Description

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

References (10)

Core 10
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110780995232064&w=2
Exploit x_refsource_misc
http://www.mikx.de/firedragging/
Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=279945
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100033
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19823
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_04_25.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12468

Scores

EPSS 0.0326
EPSS Percentile 87.0%

Details

Status published
Products (1)
mozilla/firefox 1.0
Published May 02, 2005
Tracked Since Feb 18, 2026