When handling the filename directive in the Content...
High severity
Unreviewed
Published
Jun 2, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jun 2, 2023
Published to the GitHub Advisory Database
Jun 2, 2023
Last updated
Apr 4, 2024
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
References