First published: Tue Jan 23 2018(Updated: )
Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an Internationalized Domain Name (IDN) this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <58 | 58 |
<58 | 58 | |
Mozilla Firefox | <=57.0.4 | |
Apple Mac OS X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-5121 is a vulnerability that affects certain fonts in Mozilla Firefox on OS X, allowing for domain name spoofing attacks.
CVE-2018-5121 affects OS X by causing low descenders on some Tibetan characters in certain fonts to be clipped when rendered in the address bar.
No, CVE-2018-5121 only affects OS X operating systems.
CVE-2018-5121 has a severity score of 5.3 (medium).
To fix CVE-2018-5121, update Mozilla Firefox to version 58 or later.