Firefox contains a flaw that may allow a malicious user to spoof file extensions in the file download dialog. The issue is due to the truncation of long filenames. It is possible that the flaw may allow an attacker spoof the file extension resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Attack Type Unknown
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade to version 1.0 Preview Release or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.