By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2020-03-02T04:05:03
Updated: 2024-08-04T09:11:05.129Z
Reserved: 2020-01-10T00:00:00
Link: CVE-2020-6797
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-02T05:15:13.277
Modified: 2024-11-21T05:36:12.037
Link: CVE-2020-6797
Redhat