Описание
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 51.0.1+build2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [51.0.1+build2-0ubuntu0.14.04.1]] |
| precise | released | 51.0.1+build2-0ubuntu0.12.04.1 |
| trusty | released | 51.0.1+build2-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [51.0.1+build2-0ubuntu0.14.04.1] |
| upstream | released | 51 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | released | 51.0.1+build2-0ubuntu0.16.04.1 |
| yakkety | released | 51.0.1+build2-0ubuntu0.16.10.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1:45.7.0+build1-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1:45.7.0+build1-0ubuntu0.14.04.1]] |
| precise | released | 1:45.7.0+build1-0ubuntu0.12.04.1 |
| trusty | released | 1:45.7.0+build1-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [1:45.7.0+build1-0ubuntu0.14.04.1] |
| upstream | needs-triage | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | released | 1:45.7.0+build1-0ubuntu0.16.04.1 |
| yakkety | released | 1:45.7.0+build1-0ubuntu0.16.10.1 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
URLs containing certain unicode glyphs for alternative hyphens and quo ...
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3