CVE-2017-7825
Gentoo Linux Security Advisory 201803-14
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Varias fuentes en OS X muestran caracteres Tibetan y Arabic como espacios en blanco. Cuando se utilizan en la barra de direcciones como parte de un IDN, se puede utilizar para realizar ataques de suplantación de nombres de dominio. Nota: Este ataque solo afecta a sistemas operativos OS X. Los otros sistemas operativos no se ven afectados. Esta vulnerabilidad afecta a las versiones anteriores a la 56 de Firefox, las versiones anteriores a la 52.4 de Firefox ESR y las versiones anteriores a la 52.4 de Thunderbird.
Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could lead to the execution of arbitrary code. Versions less than 52.6.0 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-12 CVE Reserved
- 2018-03-28 CVE Published
- 2024-08-05 CVE Updated
- 2025-05-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101059 | Third Party Advisory | |
http://www.securitytracker.com/id/1039465 | Third Party Advisory | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1390980 | Issue Tracking | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1393624 | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00000.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201803-14 | 2018-08-06 | |
https://www.mozilla.org/security/advisories/mfsa2017-21 | 2018-08-06 | |
https://www.mozilla.org/security/advisories/mfsa2017-22 | 2018-08-06 | |
https://www.mozilla.org/security/advisories/mfsa2017-23 | 2018-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 56.0 Search vendor "Mozilla" for product "Firefox" and version " < 56.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 52.4.0 Search vendor "Mozilla" for product "Firefox Esr" and version " < 52.4.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 52.4.0 Search vendor "Mozilla" for product "Thunderbird" and version " < 52.4.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
|