Related Vulnerabilities: CVE-2017-5383  

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display in Firefox < 51 and Thunderbird < 45.7, allowing for domain name spoofing attacks in the location bar.

Severity Medium

Remote Yes

Type Content spoofing

Description

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display in Firefox < 51 and Thunderbird < 45.7, allowing for domain name spoofing attacks in the location bar.

AVG-158 thunderbird 45.6.0-1 45.7.0-1 Critical Fixed

AVG-157 firefox 50.1.0-1 51.0.1-1 Critical Fixed

29 Jan 2017 ASA-201701-40 AVG-158 thunderbird Critical multiple issues

29 Jan 2017 ASA-201701-39 AVG-157 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5383
https://bugzilla.mozilla.org/show_bug.cgi?id=1323338
https://bugzilla.mozilla.org/show_bug.cgi?id=1324716