CVE-2021-43533 Information

Description

When parsing internationalized domain names high bits of the characters in the URLs were sometimes stripped resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1724233 https://www.mozilla.org/security/advisories/mfsa2021-48/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: