CVE-2017-7764Improper Input Validation in Mozilla Firefox

Severity
5.3MEDIUMNVD
OSV9.8
EPSS
1.0%
top 22.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unico

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages9 packages

debiandebian/firefox< firefox 54.0-1 (sid)
CVEListV5mozilla/firefoxunspecified54
NVDmozilla/firefox< 52.2.0+1
debiandebian/firefox-esr< firefox 54.0-1 (sid)
CVEListV5mozilla/firefox_esrunspecified52.2

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
GHSA
GHSA-mc3w-fw7x-qrw7: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rende2022-05-14
OSV
CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rende2018-06-11
OSV
thunderbird vulnerabilities2017-07-05
OSV
firefox vulnerabilities2017-06-15

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2017-07-05
Ubuntu
Firefox vulnerabilities2017-06-15
Red Hat
Mozilla: Domain spoofing with combination of Canadian Syllabics and other unicode blocks (MFSA 2017-16)2017-06-14
Debian
CVE-2017-7764: firefox - Characters from the "Canadian Syllabics" unicode block can be mixed with charact...2017

💬Community

2
Bugzilla
CVE-2017-7764 Mozilla: Domain spoofing with combination of Canadian Syllabics and other unicode blocks (MFSA 2017-16)2017-06-14
Bugzilla
Security: disallow "Canadian Syllabics" unicode block from IDN domains2017-05-12