CVE-2009-3376

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Date published : 2009-10-29

http://www.mozilla.org/security/announce/2009/mfsa2009-62.html

https://bugzilla.mozilla.org/show_bug.cgi?id=511521