Address bar spoofing in Mozilla Firefox - CVE-2017-5451

 

Address bar spoofing in Mozilla Firefox - CVE-2017-5451

Published: April 20, 2017


Vulnerability identifier: #VU6356
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5451
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof browser address bar.

The vulnerability exists due to an error when processing onblur event. A remote attacker can spoof the addressbar through the user interaction on the addressbar and the onblur event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar.

This vulnerability affects only Firefox for Android.


Affected software

Mozilla Firefox
Arch Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Mozilla Thunderbird

How to mitigate CVE-2017-5451

Update to Firefox 53.


External References

Related Security Bulletins