PT-2023-6538 · Mozilla+9 · Firefox+11

Armin Ebert

·

Published

2023-10-24

·

Updated

2025-03-14

·

CVE-2023-5732

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 117 Firefox ESR versions prior to 115.4 Thunderbird versions prior to 115.4.1
Description The issue is related to errors in the representation of information in the user interface, allowing an attacker to conduct spoofing attacks using a specially crafted link. This can be achieved by creating a malicious link using bidirectional characters to spoof the location in the address bar when visited.
Recommendations For Firefox versions prior to 117, update to version 117 or later to resolve the issue. For Firefox ESR versions prior to 115.4, update to version 115.4 or later to resolve the issue. For Thunderbird versions prior to 115.4.1, update to version 115.4.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of bidirectional characters in links until a patch is available.

Exploit

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6187
ALSA-2023:6188
ALSA-2023:6191
ALSA-2023:6194
ALT-PU-2023-6856
ALT-PU-2023-6883
ALT-PU-2023-6908
ALT-PU-2024-13898
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-3860
ALT-PU-2024-4241
ALT-PU-2024-4748
BDU:2023-07285
CESA-2023_6187
CESA-2023_6194
CVE-2023-5732
DLA-3632-1
DLA-3637-1
DSA-5535-1
DSA-5538-1
MGASA-2023-0308
MGASA-2023-0309
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2023_4302-1
OPENSUSE-SU-2023_4551-1
OPENSUSE-SU-2024:13356-1
OPENSUSE-SU-2024:13412-1
RHSA-2023:6162
RHSA-2023:6185
RHSA-2023:6186
RHSA-2023:6187
RHSA-2023:6188
RHSA-2023:6189
RHSA-2023:6191
RHSA-2023:6194
RHSA-2023:6195
RHSA-2023:6196
RHSA-2023:6197
RHSA-2023:6198
RHSA-2023:6199
RHSA-2023_6162
RHSA-2023_6187
RHSA-2023_6188
RHSA-2023_6191
RHSA-2023_6194
RLSA-2023:6188
SUSE-SU-2023:4302-1
SUSE-SU-2023:4532-1
SUSE-SU-2023:4533-1
SUSE-SU-2023:4551-1
USN-6468-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Suse
Thunderbird
Ubuntu