HTTP: Firefox Image Dragging

This signature detects attempts to exploit a known vulnerability in Mozilla Firefox. An attacker can craft a malicious file that contains both valid image data and malicious code, which will be executed when the user double-clicks on the saved file.

Extended Description

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

Affected Products

Mozilla firefox

References

CVE: CVE-2005-0230

Short Name
HTTP:STC:IMG:FIREFOX-IMG-DRAG
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2005-0230 Dragging Firefox Image
Release Date
03/06/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Mozilla

CVSS Score

5.1

Found a potential security threat?