CVE-2013-1699 Information

Description

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com .name and .net top-level domains which allows remote attackers to spoof the address bar via unspecified homograph characters.

Reference

http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html http://www.mozilla.org/security/announce/2013/mfsa2013-61.html http://www.ubuntu.com/usn/USN-1890-1 https://bugzilla.mozilla.org/show_bug.cgi?id=840882 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A17296

Share on: