CVE-2017-7764
Summary
| CVE | CVE-2017-7764 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2018-08-13 19:37:00 UTC |
| Description | Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Firefox Multiple Bugs Let Remote Users Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code and Let Local Users Gain Elevated Privileges - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Thunderbird 52.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| 1364283 - (CVE-2017-7764) Security: disallow "Canadian Syllabics" unicode block from IDN domains |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-3881-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 52.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| UAX #31: Unicode Identifier and Pattern Syntax |
MISC |
www.unicode.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 54 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3918-1 icedove |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378160 Virtuozzo Linux Security Update for firefox (VZLSA-2017:1440)
- 378205 Virtuozzo Linux Security Update for thunderbird (VZLSA-2017:1561)
- 710287 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201802-03)