PT-2019-4554 · Mozilla+3 · Firefox+3

U543083

·

Publicado

2019-07-11

·

Atualizado

2024-12-12

·

CVE-2019-11721

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 68
Description The issue is related to an error in encoding the Latin symbol 'kra', which can be used to substitute the standard 'k' symbol in the address bar. This can lead to domain spoofing attacks, as the symbol does not display as punycode text, potentially causing user confusion.
Recommendations For versions prior to 68, update to version 68 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the kra symbol in the address bar until the update is applied. Restrict access to potentially spoofed domains to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2301
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2020-00600
CVE-2019-11721
MGASA-2019-0213
MGASA-2019-0272
OPENSUSE-SU-2019:2248-1
OPENSUSE-SU-2019:2249-1
OPENSUSE-SU-2019:2251-1
OPENSUSE-SU-2019:2260-1
OPENSUSE-SU-2019_2248-1
OPENSUSE-SU-2019_2249-1
OPENSUSE-SU-2019_2251-1
OPENSUSE-SU-2019_2260-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:2515-1
SUSE-SU-2019:2545-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14246-1
USN-4054-1
USN-4054-2

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu