CVE-2018-5173 Information
Feb 14, 2021
cve
Description
The filename appearing in the \Downloads\ panel improperly renders some Unicode characters allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full correct filename and whether it is executable or not. This vulnerability affects Firefox 60.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
http://www.securityfocus.com/bid/104139 http://www.securitytracker.com/id/1040896 https://bugzilla.mozilla.org/show_bug.cgi?id=1438025 https://usn.ubuntu.com/3645-1/ https://www.mozilla.org/security/advisories/mfsa2018-11/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.3
Share on: