Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11721

Опубликовано: 23 июл. 2019
Источник: debian
EPSS Низкий

Описание

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed68.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11721

EPSS

Процентиль: 68%
0.00572
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 5.8
redhat
больше 6 лет назад

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 6.5
nvd
больше 6 лет назад

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 6.5
github
больше 3 лет назад

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость браузера Firefox, связанная с ошибкой кодировки латинского символа kra, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 68%
0.00572
Низкий