Spoofing attack in Mozilla Firefox - CVE-2018-5173

 

Spoofing attack in Mozilla Firefox - CVE-2018-5173

Published: May 10, 2018


Vulnerability identifier: #VU12559
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5173
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct spoofing attack.

The vulnerability exists due to the filename appearing in the Downloads panel improperly renders some Unicode characters. A remote attacker can spoof the filename and obscure the file extension of potentially executable files from user view in the panel.


Affected software

Mozilla Firefox
Arch Linux

How to mitigate CVE-2018-5173

Update to version 60.0.


External References

Related Security Bulletins