Punycode Spoofing Vulnerability in Thunderbird and Firefox

Punycode Spoofing Vulnerability in Thunderbird and Firefox

CVE-2017-5383 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Learn more about our Web Application Penetration Testing UK.