CVE-2020-35112

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:26

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1661365 - Permissions Required () https://bugzilla.mozilla.org/show_bug.cgi?id=1661365 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2020-54/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2020-54/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2020-55/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2020-55/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2020-56/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2020-56/ - Vendor Advisory

Information

Published : 2021-01-07 14:15

Updated : 2024-11-21 05:26


NVD link : CVE-2020-35112

Mitre link : CVE-2020-35112

CVE.ORG link : CVE-2020-35112


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr

microsoft

  • windows