The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 0.10.1 | 0.10.1.x |
| mozilla / firefox | 1.0 | 1.0.x |