CVE-2018-5173
critical
CVSS v3
—
CVSS v2
—
VIR risk
9.5
Description
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-5173
Vendor advisory: arch — https://security.archlinux.org/ASA-201805-10
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 60.0-1 | |
| debian | sid | fixed | 60.0-1 |
References
Verify integrity in audit chain (admin only). AS-IS.