First published: Tue Nov 15 2022(Updated: )
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <107 | 107 |
Mozilla Firefox | <107.0 | |
<107.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-45415 is a vulnerability in Mozilla Firefox that allows malicious files to be saved with incorrect extensions, potentially leading to system compromise.
CVE-2022-45415 affects Mozilla Firefox versions up to and excluding version 107.
CVE-2022-45415 has a severity level of medium.
CVE-2022-45415 can be exploited when downloading an HTML file with a maliciously formatted title.
Yes, Mozilla has released a remedy for CVE-2022-45415 in Firefox version 107.