The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104139 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040896 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 | Issue Tracking Permissions Required Vendor Advisory |
https://usn.ubuntu.com/3645-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-11/ | Vendor Advisory |
http://www.securityfocus.com/bid/104139 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040896 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 | Issue Tracking Permissions Required Vendor Advisory |
https://usn.ubuntu.com/3645-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-11/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 04:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/104139 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1040896 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 - Issue Tracking, Permissions Required, Vendor Advisory | |
References | () https://usn.ubuntu.com/3645-1/ - Third Party Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2018-11/ - Vendor Advisory |
Information
Published : 2018-06-11 21:29
Updated : 2024-11-21 04:08
NVD link : CVE-2018-5173
Mitre link : CVE-2018-5173
CVE.ORG link : CVE-2018-5173
JSON object : View
Products Affected
canonical
- ubuntu_linux
mozilla
- firefox
CWE
CWE-20
Improper Input Validation