The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104139 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040896 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 | Issue Tracking Vendor Advisory Permissions Required |
https://usn.ubuntu.com/3645-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-11/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2018-06-12T09:57:01
Reserved: 2018-01-03T00:00:00
Link: CVE-2018-5173
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-06-11T21:29:15.937
Modified: 2018-08-03T14:43:09.280
Link: CVE-2018-5173
JSON object: View
Redhat Information
No data.
CWE