CVE-2020-15658: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
  • Mozilla Firefox: before 79.0 (fixed in 79.0)
  • Mozilla Firefox ESR: before 78.1 (fixed in 78.1)
  • Mozilla Thunderbird: before 78.1 (fixed in 78.1)

Published 2020-08-10. Last modified 2026-06-17.