Bug 1861647 (CVE-2020-15658)

Summary: CVE-2020-15658 Mozilla: Overriding file type when saving to disk
Product: [Other] Security Response Reporter: Doran Moppert <dmoppert>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: cschalle, gecko-bugs-nobody, jhorak, stransky
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: thunderbird 78.1, firefox 78.1, firefox 79 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-08-20 03:15:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1870416, 1870417, 1870418, 1873379    
Bug Blocks: 1861032    

Description Doran Moppert 2020-07-29 07:03:30 UTC
The code for downloading files did not properly take care of special characters,
which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog.



External Reference:

https://www.mozilla.org/en-US/security/advisories/mfsa2020-33/#CVE-2020-15658

Comment 1 Doran Moppert 2020-07-29 07:03:34 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: belden

Comment 2 Product Security DevOps Team 2020-08-20 03:15:26 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-15658

Comment 3 errata-xmlrpc 2020-08-26 08:31:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions

Via RHSA-2020:3555 https://access.redhat.com/errata/RHSA-2020:3555

Comment 4 errata-xmlrpc 2020-08-26 08:46:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:3557 https://access.redhat.com/errata/RHSA-2020:3557

Comment 5 errata-xmlrpc 2020-08-26 10:09:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2020:3559 https://access.redhat.com/errata/RHSA-2020:3559

Comment 7 errata-xmlrpc 2020-09-30 06:35:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:4080 https://access.redhat.com/errata/RHSA-2020:4080