CVE-2005-0145: Low severity Mozilla Firefox vulnerability
Published Jan 24, 2005
·Updated
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
Affected Software
9 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Remediation
Patch Available
Patch Available
Event History
Jan 24, 2005
CVE Published
05:00 AM
Jan 29, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0145?
CVE-2005-0145 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2005-0145?
To fix CVE-2005-0145, update to a version of Firefox later than 1.0 that addresses this vulnerability.
3
What versions of Firefox are affected by CVE-2005-0145?
CVE-2005-0145 affects Firefox versions 0.8 to 1.0.
4
What does CVE-2005-0145 allow attackers to do?
CVE-2005-0145 allows attackers to bypass the file download prompt using a synthetic click event.
5
Is it safe to continue using Firefox versions affected by CVE-2005-0145?
Using Firefox versions affected by CVE-2005-0145 can expose users to potential security risks, so it is not recommended.