CVE-2005-1575: Medium severity firefox vulnerability
Published May 14, 2005
·Updated
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.
Affected Software
2 affected components
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Event History
May 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1575?
CVE-2005-1575 is considered a moderate severity vulnerability due to the potential for users to be tricked into downloading harmful files.
2
How do I fix CVE-2005-1575?
To fix CVE-2005-1575, upgrade to a later version of Mozilla Firefox that addresses this vulnerability.
3
What versions of Firefox are affected by CVE-2005-1575?
CVE-2005-1575 affects Mozilla Firefox versions 0.10.1 and 1.0.
4
Can CVE-2005-1575 be exploited remotely?
Yes, CVE-2005-1575 can be exploited remotely by attackers using crafted HTTP headers.
5
What is the nature of the vulnerability described in CVE-2005-1575?
CVE-2005-1575 allows remote attackers to obscure the true file types of downloaded files.