Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2012-09

Firefox Recovery Key.html is saved with unsafe permission

Announced
January 31, 2012
Reporter
magicant starmen
Impact
Moderate
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 10
  • SeaMonkey 2.7

Description

magicant starmen reported that if a user chooses to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users on Linux and OS X systems.

Firefox 3.6 is not affected by this vulnerability.

References