Spoofing attack in Mozilla Firefox - CVE-2017-7833

 

Spoofing attack in Mozilla Firefox - CVE-2017-7833

Published: November 15, 2017


Vulnerability identifier: #VU9320
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7833
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof domain names.

Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some font sets on the addressbar. The non-Latin character will not be visible to most viewers. This allows for domain spoofing attacks because these combined domain names do not display as punycode.


Affected software

Mozilla Firefox
Arch Linux
Ubuntu

How to mitigate CVE-2017-7833

Update to version Firefox 57.


External References

Related Security Bulletins