Closed Bug 1392190 Opened 8 years ago Closed 8 years ago

disallow "malayalam" unicode block from IDN domains

Categories

(Firefox :: Address Bar, defect)

55 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1373860

People

(Reporter: xisigr, Unassigned)

References

Details

Attachments

(1 file)

Attached image U+0D4E.png
Firefox should prevent the “malayalam” unicode block from rendering in domain names with characters from other unicode blocks. This could lead to IDN domain spoofing. Test on macOS. https://www.xn--google-1zs.com (U+0D4E)
On Mac 10.11.6 it's not a spoof at all: I get an undefined-character box. Although not strictly a combining mark, this is still basically bug 1370497 (and/or the bug where we're considering switching to the "Highly Restrictive" IDN profile).
Depends on: CVE-2017-7833
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Resolution: --- → DUPLICATE
Yeah, this one doesn't work for me on Linux. Gerv
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: