CVE-2022-45415

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-47/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-47/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 Issue Tracking Permissions Required Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

15 Apr 2025, 15:16

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 - Issue Tracking, Permissions Required, Vendor Advisory
CWE CWE-434

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1793551 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory
Summary
  • (es) Al descargar un archivo HTML, si el título de la página tenía el formato de un nombre de archivo con una extensión maliciosa, es posible que Firefox haya guardado el archivo con esa extensión, lo que podría comprometer el sistema si el archivo descargado se ejecuta más tarde. Esta vulnerabilidad afecta a Firefox &lt; 107.

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 15:16


NVD link : CVE-2022-45415

Mitre link : CVE-2022-45415

CVE.ORG link : CVE-2022-45415


JSON object : View

Products Affected

mozilla

  • firefox
CWE
NVD-CWE-noinfo CWE-434

Unrestricted Upload of File with Dangerous Type