CVE-2017-7825

NameCVE-2017-7825
DescriptionSeveral fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firefox (PTS)sid67.0.4-1fixed
firefox-esr (PTS)jessie52.8.1esr-1~deb8u1fixed
jessie (security)60.7.1esr-1~deb8u1fixed
stretch60.6.1esr-1~deb9u1fixed
stretch (security)60.7.1esr-1~deb9u1fixed
buster, sid60.7.2esr-1fixed
icedove (PTS)jessie1:52.3.0-4~deb8u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)(not affected)
firefox-esrsource(unstable)(not affected)
icedovesource(unstable)(not affected)

Notes

- firefox <not-affected> (Only affects Firefox on OS X)
- firefox-esr <not-affected> (Only affects Firefox on OS X)
- icedove <not-affected> (Only affects Thunderbird on OS X)
https://www.mozilla.org/en-US/security/advisories/mfsa2017-21/#CVE-2017-7825
https://www.mozilla.org/en-US/security/advisories/mfsa2017-22/#CVE-2017-7825
https://www.mozilla.org/en-US/security/advisories/mfsa2017-23/#CVE-2017-7825

Search for package or bug name: Reporting problems