First published: Tue May 31 2022(Updated: )
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <101 | 101 |
<101 | 101 | |
<91.10 | 91.10 | |
<91.10 | 91.10 | |
Mozilla Firefox | <101 | |
Mozilla Firefox ESR | <91.10 | |
Mozilla Thunderbird | <91.10 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)