When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1040270 | vdb entry third party advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1321619 | issue tracking permissions required |
https://usn.ubuntu.com/3544-1/ | third party advisory vendor advisory |
http://www.securityfocus.com/bid/102786 | vdb entry third party advisory |
https://www.mozilla.org/security/advisories/mfsa2018-02/ | vendor advisory |