Description
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
References (3)
Core 3
Core References
Exploit, Vendor Advisory vdb-entry
x_refsource_osvdb
http://www.osvdb.org/16432
Exploit, Patch, Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2004-11/advisory/
Exploit, Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/12979
Scores
EPSS
0.0112
EPSS Percentile
62.6%
Details
Status
published
Products (2)
mozilla/firefox
0.10.1
mozilla/firefox
1.0
Published
May 12, 2005
Tracked Since
Feb 18, 2026