Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2008-40

Forced mouse drag

Announced
September 23, 2008
Reporter
Paul Nickerson, Liu Die Yu
Impact
Low
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 2.0.0.17
  • Firefox 3.0.2
  • SeaMonkey 1.1.12

Description

Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.

Workaround

  1. open Options/Preferences dialog
  2. go to the "Content" tab
  3. click the "Advanced..." button on the same line as the "Enable JavaScript" checkbox
  4. UN-check the "Move or resize existing windows" box.

References