CVE-2017-7763: Input Validation
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-7763?
CVE-2017-7763 is classified as a moderate severity vulnerability due to its potential for domain name spoofing on OS X.
How do I fix CVE-2017-7763?
To fix CVE-2017-7763, upgrade to Mozilla Thunderbird version 52.2, Firefox ESR version 52.2, or Firefox version 54 or later.
Who is affected by CVE-2017-7763?
CVE-2017-7763 specifically affects users of Mozilla Thunderbird, Firefox ESR, and Firefox on OS X operating systems.
What type of attack does CVE-2017-7763 enable?
CVE-2017-7763 enables domain name spoofing attacks through improper rendering of Tibetan characters in the OS X address bar.
Is CVE-2017-7763 a risk for other operating systems?
No, CVE-2017-7763 only affects OS X operating systems and does not pose a risk to other platforms.