Spoofing attack in Mozilla Firefox - CVE-2018-5173
Published: May 10, 2018
Vulnerability identifier: #VU12559
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5173
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct spoofing attack.
The vulnerability exists due to the filename appearing in the Downloads panel improperly renders some Unicode characters. A remote attacker can spoof the filename and obscure the file extension of potentially executable files from user view in the panel.
Affected software
Mozilla Firefox
Arch Linux
Arch Linux
How to mitigate CVE-2018-5173
Update to version 60.0.