CVE-2005-0230
Firefox 1.0 - Arbitrary Command Execution via Malformed GIF File Dragging
Title source: llmDescription
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
References (10)
Core 10
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110780995232064&w=2
Exploit x_refsource_misc
http://www.mikx.de/firedragging/
Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=279945
Patch x_refsource_confirm
http://www.mozilla.org/security/announce/mfsa2005-25.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100033
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19823
Patch, Vendor Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
Patch, Vendor Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_04_25.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12468
Scores
EPSS
0.0326
EPSS Percentile
87.0%
Details
Status
published
Products (1)
mozilla/firefox
1.0
Published
May 02, 2005
Tracked Since
Feb 18, 2026