CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
Percentile
70.6%
Characters from the “Canadian Syllabics” unicode block can be mixed with
characters from other unicode blocks in the addressbar instead of being
rendered as their raw “punycode” form, allowing for domain name spoofing
attacks through character confusion. The current Unicode standard allows
characters from “Aspirational Use Scripts” such as Canadian Syllabics to be
mixed with Latin characters in the “moderately restrictive” IDN profile. We
have changed Firefox behavior to match the upcoming Unicode version 10.0
which removes this category and treats them as “Limited Use Scripts.”. This
vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird <
52.2.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | firefox | < 54.0+build3-0ubuntu0.14.04.1 | UNKNOWN |
ubuntu | 16.04 | noarch | firefox | < 54.0+build3-0ubuntu0.16.04.1 | UNKNOWN |
ubuntu | 16.10 | noarch | firefox | < 54.0+build3-0ubuntu0.16.10.1 | UNKNOWN |
ubuntu | 17.04 | noarch | firefox | < 54.0+build3-0ubuntu0.17.04.1 | UNKNOWN |
ubuntu | 14.04 | noarch | thunderbird | < 1:52.2.1+build1-0ubuntu0.14.04.1 | UNKNOWN |
ubuntu | 16.04 | noarch | thunderbird | < 1:52.2.1+build1-0ubuntu0.16.04.1 | UNKNOWN |
ubuntu | 16.10 | noarch | thunderbird | < 1:52.2.1+build1-0ubuntu0.16.10.1 | UNKNOWN |
ubuntu | 17.04 | noarch | thunderbird | < 1:52.2.1+build1-0ubuntu0.17.04.1 | UNKNOWN |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
Percentile
70.6%