CVE-2020-15658
Summary
| CVE | CVE-2020-15658 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-10 18:15:00 UTC |
| Updated | 2023-02-02 22:23:00 UTC |
| Description | The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Vulnerabilities fixed in Firefox 79 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1189-1: important: Security update |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| Security Vulnerabilities fixed in Firefox ESR 78.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security Vulnerabilities fixed in Thunderbird 78.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Access Denied |
MISC |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| USN-4443-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296071 Oracle Solaris 11.4 Support Repository Update (SRU) 27.82.1 Missing (CPUOCT2020)
- 500932 Alpine Linux Security Update for firefox-esr
- 500952 Alpine Linux Security Update for firefox
- 503837 Alpine Linux Security Update for firefox