Closed Bug 1392193 Opened 5 years ago Closed 5 years ago

disallow "lao" unicode block from IDN domains

Categories

(Firefox :: Address Bar, defect)

55 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1370497

People

(Reporter: xisigr, Unassigned)

Details

Attachments

(1 file)

Attached image U+0ECD.png
Firefox should prevent the “lao” unicode block from rendering in domain names with characters from other unicode blocks. This could lead to IDN domain spoofing.

Test on Windows,macOS.

https://www.xn--google-n6u.com (U+0ECD)
Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: CVE-2017-7833
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.