First published: Tue Apr 29 2025(Updated: )
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <138 | 138 |
Firefox | <138 | 138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of MFSA-RESERVE-2025-1945705 is classified as low due to its limited impact on users.
To fix MFSA-RESERVE-2025-1945705, users should upgrade to the latest version of Firefox and Thunderbird that exceeds version 138.
MFSA-RESERVE-2025-1945705 affects Firefox versions up to and including 138.
No, MFSA-RESERVE-2025-1945705 specifically affects Firefox for Android only.
The nature of MFSA-RESERVE-2025-1945705 is that it allows filenames with encoded newline characters to obscure their file extensions in the download dialog.