CVE-2019-17019: High severity firefox vulnerability
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. Note: this issue only occurs on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 72.
Other sources
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. Note: this issue only occurs on Windows. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17019?
CVE-2019-17019 is a vulnerability where a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download.
What is the severity of CVE-2019-17019?
The severity of CVE-2019-17019 is high with a CVSS score of 8.8.
Which operating systems are affected by CVE-2019-17019?
This vulnerability only occurs on Windows, other operating systems are unaffected.
How can I mitigate CVE-2019-17019?
To mitigate CVE-2019-17019, ensure that the python file being served has the correct MIME type set and perform proper file validation.
Is the Firefox browser affected by CVE-2019-17019?
Yes, the vulnerability affects Mozilla Firefox versions up to but not including 72.0.