Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an Internationalized Domain Name (IDN) this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 58.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1040270 | vdb entry third party advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1402368 | issue tracking permissions required |
http://www.securityfocus.com/bid/102786 | vdb entry third party advisory |
https://www.mozilla.org/security/advisories/mfsa2018-02/ | vendor advisory |