UCF STIG Viewer Logo

Firefox not configured to prompt user before download and opening for required file types.


Overview

Finding ID Version Rule ID IA Controls Severity
V-57589 DTBF-0008 SV-71999r1_rule Medium
Description
New file types cannot be added directly to the helper applications or plugins listing. Files with these extensions will not be allowed to use Firefox publicly available plugins and extensions to open. The application will be configured to open these files using external applications only. After a helper application or save to disk download action has been set, that action will be taken automatically for those types of files. When the user receives a dialog box asking if you want to save the file or open it with a specified application, this indicates that a plugin does not exist. The user has not previously selected a download action or helper application to automatically use for that type of file. When prompted, if the user checks the option to Do this automatically for files like this from now on, then an entry will appear for that type of file in the plugins listing and this file type is automatically opened in the future. This can be a security issue. New file types cannot be added directly to the Application plugin listing.
STIG Date
Mozilla Firefox 2017-03-22

Details

Check Text ( C-58421r2_chk )
Procedure:
In about:config, verify that the “plugin.disable_full_page_plugin_for_types” value is not set to include the following external extensions and not locked, then this is a finding:

PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP.

Criteria:
If the values of the listed Preferences are not set and locked to these settings, then this is a finding.
Fix Text (F-62789r2_fix)
Set and lock the following preferences using the “Mozilla.cfg” file:
"plugin.disable_full_page_plugin_for_types", set to “PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP”.