cbcvebase.
CVE-2017-5383
published 2018-06-11

CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks…

medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 51.0-1 (sid)firefox 51.0-1 (sid)
debianfirefox-esr< firefox 51.0-1 (sid)firefox 51.0-1 (sid)
mozillafirefox< 51.051.0
mozillafirefox< 45.7.045.7.0
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.14.04.151.0.1+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.14.04.251.0.1+build2-0ubuntu0.14.04.2
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.16.04.151.0.1+build2-0ubuntu0.16.04.1
mozillafirefox>= 0 < 51.0.1+build2-0ubuntu0.16.04.251.0.1+build2-0ubuntu0.16.04.2
mozillafirefox>= unspecified < 5151
mozillafirefox_esr>= unspecified < 45.745.7
mozillathunderbird< 45.7.045.7.0
mozillathunderbird>= 0 < 1:45.7.0+build1-0ubuntu0.14.04.11:45.7.0+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:45.7.0+build1-0ubuntu0.16.04.11:45.7.0+build1-0ubuntu0.16.04.1
mozillathunderbird>= unspecified < 45.745.7
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv9.8CRITICAL