Bug 963642 (CVE-2016-1941) - VUL-0: CVE-2016-1941: MozillaFirefo: Delay following click events in file download dialog too short on OS X
Summary: VUL-0: CVE-2016-1941: MozillaFirefo: Delay following click events in file dow...
Status: RESOLVED INVALID
Alias: CVE-2016-1941
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Macintosh Mac OS X 10.11
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on: 963520
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-26 18:18 UTC by Andreas Stieger
Modified: 2016-01-26 18:19 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-01-26 18:18:02 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-08/

Security researcher Jordi Chancel reported an issue on OS X where the delay between the download dialog getting focus and the button getting enabled was too short. If an attacker is able to induce the user to double-click in a specific location, they can then pass the second click through to the dialog below, leading to unintentional actions such as the running of downloaded software.

https://bugzilla.mozilla.org/show_bug.cgi?id=1116385
Comment 1 Andreas Stieger 2016-01-26 18:19:23 UTC
OS X