CVE-2023-29539
Published: Jun 2, 2023
Modified: Jan 9, 2025
Description
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 112 |
Mozilla | Focus for Android | affected unspecified - < 112 |
Mozilla | Firefox ESR | affected unspecified - < 102.10 |
Mozilla | Firefox for Android | affected unspecified - < 112 |
Mozilla | Thunderbird | affected unspecified - < 102.10 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now