Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7764

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 5.3

Описание

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

РелизСтатусПримечание
devel

released

54.0+build3-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [54.0+build3-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

54.0+build3-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [54.0+build3-0ubuntu0.14.04.1]
upstream

released

54.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

54.0+build3-0ubuntu0.16.04.1
yakkety

released

54.0+build3-0ubuntu0.16.10.1

Показывать по

РелизСтатусПримечание
devel

released

1:52.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:52.2.1+build1-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

1:52.2.1+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:52.2.1+build1-0ubuntu0.14.04.1]
upstream

released

52.2.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

1:52.2.1+build1-0ubuntu0.16.04.1
yakkety

released

1:52.2.1+build1-0ubuntu0.16.10.1

Показывать по

EPSS

Процентиль: 78%
0.01202
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 8 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
nvd
около 7 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
debian
около 7 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed wi ...

CVSS3: 5.3
github
около 3 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
fstec
около 8 лет назад

Уязвимость браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная cо смешением символов из блока «Canadian Syllabics» с символами из других блоков, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 78%
0.01202
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3