Mozilla Foundation Security Advisory 2007-22
File type confusion due to %00 in name
- Announced
- July 17, 2007
- Reporter
- Ronald van den Heetkamp
- Impact
- Low
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 2.0.0.5
- SeaMonkey 1.1.3
Description
Ronald van den Heetkamp reported that a filename URL containing %00 (encoded null) can cause Firefox to interpret the file extension differently than the underlying Windows operating system potentially leading to unsafe actions such as running a program. This is only accessible locally.