Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7764

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 5.3

Описание

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

РелизСтатусПримечание
devel

released

54.0+build3-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [54.0+build3-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

54.0+build3-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [54.0+build3-0ubuntu0.14.04.1]
upstream

released

54.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

54.0+build3-0ubuntu0.16.04.1
yakkety

released

54.0+build3-0ubuntu0.16.10.1

Показывать по

РелизСтатусПримечание
devel

released

1:52.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:52.2.1+build1-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

1:52.2.1+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:52.2.1+build1-0ubuntu0.14.04.1]
upstream

released

52.2.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

1:52.2.1+build1-0ubuntu0.16.04.1
yakkety

released

1:52.2.1+build1-0ubuntu0.16.10.1

Показывать по

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 8 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
nvd
больше 7 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
debian
больше 7 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed wi ...

CVSS3: 5.3
github
больше 3 лет назад

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 5.3
fstec
больше 8 лет назад

Уязвимость браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная cо смешением символов из блока «Canadian Syllabics» с символами из других блоков, позволяющая нарушителю проводить спуфинг-атаки

5 Medium

CVSS2

5.3 Medium

CVSS3