CVE-2018-5173

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.
References
Link Resource
http://www.securityfocus.com/bid/104139 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040896 Third Party Advisory VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 Issue Tracking Vendor Advisory Permissions Required
https://usn.ubuntu.com/3645-1/ Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2018-11/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-11 21:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-5173

Mitre link : CVE-2018-5173

CVE.ORG link : CVE-2018-5173


JSON object : View

Products Affected

mozilla

  • firefox

canonical

  • ubuntu_linux
CWE
CWE-20

Improper Input Validation