Mozilla Foundation Security Advisory 2014-03

UI selection timeout missing on download prompts

Announced
February 4, 2014
Reporter
Jordi Chancel
Impact
Moderate
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 27
  • SeaMonkey 2.24

Description

Security researcher Jordi Chancel reported that the dialog for saving downloaded files did not implement a security timeout before button selections were processed. This could be used in concert with spoofing to convince users to select a different option than intended, causing downloaded files to be potentially opened instead of only saved in some circumstances.

In general this flaw cannot be exploited through email in the Seamonkey product because scripting is disabled in mail, but is potentially a risk in browser or browser-like contexts.

References