First published: Tue Mar 07 2017(Updated: )
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displayed location following navigation does not match the URL of the newly loaded page. This allows for spoofing attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <52 | 52 |
Firefox | <52.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5417 has a moderate severity rating due to its potential for spoofing attacks.
To mitigate CVE-2017-5417, users should update Mozilla Firefox to version 53 or later.
CVE-2017-5417 allows attackers to manipulate the address bar, leading to user deception and possible phishing attempts.
CVE-2017-5417 affects Mozilla Firefox versions below 53.
Exploitation of CVE-2017-5417 requires user interaction through dragging content, which makes it dependent on user behavior.