THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-29539 (HIGH 8.8) — When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Fir

[NVD] CVE-2023-29539 (HIGH 8.8) — When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Fir

lownvdPublished 2023-06-02

CVE-2023-29539 CVSS: 8.8 HIGH Published: 2023-06-02T17:15:12.607

When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-29539