Domain name spoofing in Mozilla Firefox - CVE-2017-7825
Published: September 28, 2017 / Updated: September 29, 2017
Vulnerability identifier: #VU8625
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7825
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks.
Note: This attack only affects OS X operating systems. Other operating systems are unaffected.
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks.
Note: This attack only affects OS X operating systems. Other operating systems are unaffected.
Affected software
Mozilla Firefox
Firefox ESR
Gentoo Linux
SUSE Linux
Mozilla Thunderbird
Firefox ESR
Gentoo Linux
SUSE Linux
Mozilla Thunderbird
How to mitigate CVE-2017-7825
Update to version 56.0.
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- SUSE Linux update for MozillaFirefox
- SUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaThunderbird
- SUSE Linux update for MozillaFirefox
- Gentoo update for Mozilla Thunderbird