Back

MEDIUM

firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)

Published Feb 20, 2009

Description

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2009
Updated Aug 7, 2024
Reserved Feb 20, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 16, 2009