CVE-2017-7764

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
mozillafirefox
𝑥
< 54.0
mozillafirefox_esr
𝑥
< 52.2.0
mozillathunderbird
𝑥
< 52.2.0
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
132.0.1-1
fixed
firefox-esr
bullseye
115.14.0esr-1~deb11u1
fixed
bullseye (security)
128.4.0esr-1~deb11u1
fixed
bookworm
115.14.0esr-1~deb12u1
fixed
bookworm (security)
128.4.0esr-1~deb12u1
fixed
trixie
128.3.1esr-2
fixed
sid
128.4.0esr-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
zesty
Fixed 54.0+build3-0ubuntu0.17.04.1
released
yakkety
Fixed 54.0+build3-0ubuntu0.16.10.1
released
xenial
Fixed 54.0+build3-0ubuntu0.16.04.1
released
trusty
Fixed 54.0+build3-0ubuntu0.14.04.1
released
thunderbird
zesty
Fixed 1:52.2.1+build1-0ubuntu0.17.04.1
released
yakkety
Fixed 1:52.2.1+build1-0ubuntu0.16.10.1
released
xenial
Fixed 1:52.2.1+build1-0ubuntu0.16.04.1
released
trusty
Fixed 1:52.2.1+build1-0ubuntu0.14.04.1
released