First published: Tue Jan 07 2020(Updated: )
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 72.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <72 | 72 |
<72 | 72 | |
Mozilla Firefox | <72.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-17019 is a vulnerability where a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download.
The severity of CVE-2019-17019 is high with a CVSS score of 8.8.
This vulnerability only occurs on Windows, other operating systems are unaffected.
To mitigate CVE-2019-17019, ensure that the python file being served has the correct MIME type set and perform proper file validation.
Yes, the vulnerability affects Mozilla Firefox versions up to but not including 72.0.