First published: Thu Sep 28 2017(Updated: )
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <52.4 | 52.4 |
<56 | 56 | |
<52.4 | 52.4 | |
<52.4 | 52.4 | |
Debian Debian Linux | =7.0 | |
Mozilla Firefox | <56.0 | |
Mozilla Firefox ESR | <52.4.0 | |
Mozilla Thunderbird | <52.4.0 | |
Apple Mac OS X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-7825.
This vulnerability only affects OS X operating systems.
Mozilla Thunderbird version up to and including 52.4, Mozilla Firefox version up to and including 56, and Mozilla Firefox ESR version up to and including 52.4 are affected.
The severity of CVE-2017-7825 is medium with a severity value of 5.3.
To fix the vulnerability, update to the latest version of Mozilla Thunderbird, Mozilla Firefox, or Mozilla Firefox ESR.