CVE-2020-35112
Summary
| CVE | CVE-2020-35112 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-07 14:15:00 UTC |
| Updated | 2021-01-12 19:01:00 UTC |
| Description | If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerabilities fixed in Firefox ESR 78.6 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Security Vulnerabilities fixed in Firefox 84 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Security Vulnerabilities fixed in Thunderbird 78.6 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Access Denied | MISC | bugzilla.mozilla.org | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500938 Alpine Linux Security Update for firefox-esr
- 500958 Alpine Linux Security Update for firefox
- 502377 Alpine Linux Security Update for thunderbird
- 503843 Alpine Linux Security Update for firefox
- 750467 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2020:2325-1)
- 750468 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2020:2324-1)
- 750469 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2020:2317-1)
- 750470 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2020:2318-1)
- 750471 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2020:2317-1)