A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 59.
References
Link Resource
http://www.securityfocus.com/bid/103386 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040514 Third Party Advisory VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1432624 Issue Tracking Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-06/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2018-06-12T09:57:01

Reserved: 2018-01-03T00:00:00


Link: CVE-2018-5138

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-11T21:29:14.483

Modified: 2018-08-08T18:36:29.017


Link: CVE-2018-5138

JSON object: View

cve-icon Redhat Information

No data.

CWE